Severity Rating: Critical - Revision Note: V1.1 (April 16, 2009): Added a warning message to the workarounds for disabling the converters, stating you must undo the workaround before installing this security update. This is an informational change only.Summary: This security update resolves two publicly disclosed vulnerabilities and two privately reported vulnerabilities in Microsoft WordPad and Microsoft Office text converters. The vulnerabilities could allow remote code execution if a specially crafted file is opened in WordPad or Microsoft Office Word. Do not open Microsoft Office, RTF, Write, or WordPerfect files from untrusted sources using affected versions of WordPad or Microsoft Office Word.
More...