Microsoft Word OLE32.dll Library Security Bypass Vulnerability
BID:107297
Info
Microsoft Word OLE32.dll Library Security Bypass Vulnerability
| Bugtraq ID: | 107297 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 05 2019 12:00AM |
| Updated: | Mar 05 2019 12:00AM |
| Credit: | Mimecast |
| Vulnerable: |
Microsoft Word 0 Microsoft Windows 0 Microsoft Office 0 |
| Not Vulnerable: | |
Discussion
Microsoft Word OLE32.dll Library Security Bypass Vulnerability
Microsoft Word is prone to a memory-corruption vulnerability.
An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions.
Microsoft Word is prone to a memory-corruption vulnerability.
An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions.
Exploit / POC
Microsoft Word OLE32.dll Library Security Bypass Vulnerability
Reports indicate that this issue is being exploited in the wild. Please see the references for more information.
Reports indicate that this issue is being exploited in the wild. Please see the references for more information.
Solution / Fix
Microsoft Word OLE32.dll Library Security Bypass Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Microsoft Word OLE32.dll Library Security Bypass Vulnerability
References:
References:
- RSAC 2019: Microsoft Zero-Day Allows Exploits to Sneak Past Sandboxes (threatpost.com)
- Microsoft Homepage (Microsoft)