

The following software have been tested to determine which versions or editions are affected.

The article also documents recommended solutions for these issues. Microsoft Knowledge Base Article 960477 documents the currently known issues that customers may experience when installing this security update.
UPDATE MICROSOFT WORD 97 UPDATE
Recommendation. Microsoft recommends that customers apply the update immediately. This security update also addresses the vulnerability first described in Microsoft Security Advisory 960906. For more information about the vulnerabilities, see the Frequently Asked Questions (FAQ) subsection for the specific vulnerability entry under the next section, Vulnerability Information. This security update also addresses the vulnerabilities by implementing fixes to WordPad and by preventing WordPad on affected platforms from opening Word 6.0 and Windows Write files. This security update addresses the vulnerabilities by modifying the way that Microsoft Office Word and Office text converters handle opening specially crafted Word 6.0, Windows Write, and WordPerfect documents. For more information, see the subsection, Affected and Non-Affected Software, in this section. This security update is also rated Important for supported editions of Microsoft Office Word 2002 Microsoft Office Converter Pack and WordPad on all supported editions of Microsoft Windows 2000, Windows XP, and Windows Server 2003.

This security update is rated Critical for supported editions of Microsoft Office Word 2000. Do not open Microsoft Office, RTF, Write, or WordPerfect files from untrusted sources using affected versions of WordPad or Microsoft Office Word. The vulnerabilities could allow remote code execution if a specially crafted file is opened in WordPad or Microsoft Office Word. This security update resolves two publicly disclosed vulnerabilities and two privately reported vulnerabilities in Microsoft WordPad and Microsoft Office text converters. Version: 1.3 General Information Executive Summary Security Bulletin Microsoft Security Bulletin MS09-010 - Critical Vulnerabilities in WordPad and Office Text Converters Could Allow Remote Code Execution (960477)
