Microsoft Step-By-Step Interactive Training Bookmark Link Buffer Overflow Vulnerability
BID:13944
Info
Microsoft Step-By-Step Interactive Training Bookmark Link Buffer Overflow Vulnerability
| Bugtraq ID: | 13944 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-1212 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 14 2005 12:00AM |
| Updated: | Jul 12 2009 02:56PM |
| Credit: | Discovery is credited to iDEFENSE Labs. |
| Vulnerable: |
Microsoft Step-By-Step Interactive 0 |
| Not Vulnerable: | |
Discussion
Microsoft Step-By-Step Interactive Training Bookmark Link Buffer Overflow Vulnerability
Microsoft Step-By-Step Interactive Training is prone to a buffer overflow vulnerability. This is due to a boundary condition error related to validation of data in bookmark link files. As bookmark link files may originate from an external source, this issue may be remotely exploitable.
Successful exploitation will result in execution of arbitrary code in the context of the currently logged in user.
A number of third-party providers may supply the Step-by-Step Interactive training program as a part of their products. There is not a conclusive list of products that may have installed this software.
Microsoft Step-By-Step Interactive Training is prone to a buffer overflow vulnerability. This is due to a boundary condition error related to validation of data in bookmark link files. As bookmark link files may originate from an external source, this issue may be remotely exploitable.
Successful exploitation will result in execution of arbitrary code in the context of the currently logged in user.
A number of third-party providers may supply the Step-by-Step Interactive training program as a part of their products. There is not a conclusive list of products that may have installed this software.
Exploit / POC
Microsoft Step-By-Step Interactive Training Bookmark Link Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft Step-By-Step Interactive Training Bookmark Link Buffer Overflow Vulnerability
Solution:
Microsoft has released fixes to address this vulnerability.
Microsoft Step-By-Step Interactive 0
Solution:
Microsoft has released fixes to address this vulnerability.
Microsoft Step-By-Step Interactive 0
-
Microsoft Security Update for Windows (KB898458)
http://www.microsoft.com/downloads/details.aspx?FamilyId=591265a7-e7f4 -409f-992b-84d954824ba8
References
Microsoft Step-By-Step Interactive Training Bookmark Link Buffer Overflow Vulnerability
References:
References: