CVE-2018-3933: Antennahouse Office Server Document Converter

High severity, CVSS 7.8. EPSS: 2.1% chance of exploitation in the next 30 days.

An exploitable out-of-bounds write exists in the Microsoft Word document conversion functionality of the Antenna House Office Server Document Converter version V6.1 Pro MR2 for Linux64 (6,1,2018,0312). A crafted Microsoft Word (DOC) document can lead to an out-of-bounds write, resulting in remote code execution. This vulnerability occurs in the `vbputanld` method.

Affected products

  • Antennahouse Office Server Document Converter: version 6.1 only

Published 2018-07-11. Last modified 2026-06-17.