Microsoft Word Malformed Object Pointer Remote Code Execution Vulnerability
BID:18037
Info
Microsoft Word Malformed Object Pointer Remote Code Execution Vulnerability
| Bugtraq ID: | 18037 |
| Class: | Unknown |
| CVE: |
CVE-2006-2492 |
| Remote: | Yes |
| Local: | No |
| Published: | May 19 2006 12:00AM |
| Updated: | Jun 15 2006 11:31PM |
| Credit: | Shih-hao Weng of Information & Communication Security Technology Center reported this issue to the vendor. Andreas Marx of AV-Test.org is also credited for assisting Microsoft with this issue. |
| Vulnerable: |
Microsoft Works Suite 2006 0 Microsoft Works Suite 2005 0 Microsoft Works Suite 2004 Microsoft Works Suite 2003 Microsoft Works Suite 2002 Microsoft Works Suite 2001 Microsoft Works Suite 2000 0 Microsoft Word Viewer 2003 0 Microsoft Word 2003 Microsoft Word 2002 SP3 Microsoft Word 2002 SP2 Microsoft Word 2002 SP1 Microsoft Word 2002 |
| Not Vulnerable: |
Microsoft Word X for Mac Microsoft Office X for Mac 0 Microsoft Excel 2004 for Mac 0 |
Discussion
Microsoft Word Malformed Object Pointer Remote Code Execution Vulnerability
Microsoft Word is prone to a remote code-execution vulnerability. The issue arises because Word fails to properly handle malformed object pointers.
Reports indicate that this issue can allow remote attackers to execute arbitrary code on a vulnerable computer by supplying a malicious Word document to a user. This issue is being actively exploited in the wild to place a backdoor named Backdoor.Ginwui on targeted computers through a trojan named Trojan.Mdropper.H.
Microsoft Word is prone to a remote code-execution vulnerability. The issue arises because Word fails to properly handle malformed object pointers.
Reports indicate that this issue can allow remote attackers to execute arbitrary code on a vulnerable computer by supplying a malicious Word document to a user. This issue is being actively exploited in the wild to place a backdoor named Backdoor.Ginwui on targeted computers through a trojan named Trojan.Mdropper.H.
Exploit / POC
Microsoft Word Malformed Object Pointer Remote Code Execution Vulnerability
An exploit is known to be in the wild.
Immunity has developed a proof-of-concept exploit for this issue. This exploit is available only as part of the Immunity Partner program; it is not available to the public.
An exploit is known to be in the wild.
Immunity has developed a proof-of-concept exploit for this issue. This exploit is available only as part of the Immunity Partner program; it is not available to the public.
Solution / Fix
Microsoft Word Malformed Object Pointer Remote Code Execution Vulnerability
Solution:
Microsoft has released fixes for this issue:
Microsoft Word 2002 SP2
Microsoft Word 2003
Microsoft Word 2002 SP1
Microsoft Word Viewer 2003 0
Microsoft Word 2002
Microsoft Works Suite 2003
Microsoft Word 2002 SP3
Microsoft Works Suite 2002
Microsoft Works Suite 2000 0
Microsoft Works Suite 2006 0
Microsoft Works Suite 2005 0
Microsoft Works Suite 2001
Microsoft Works Suite 2004
Solution:
Microsoft has released fixes for this issue:
Microsoft Word 2002 SP2
-
Microsoft Security Update for Word 2002 (KB917335)
http://www.microsoft.com/downloads/details.aspx?familyid=4CDE644B-BE05 -4680-B0EF-DF563095563C&displaylang=en
Microsoft Word 2003
-
Microsoft Security Update for Word 2003 (KB917334)
http://www.microsoft.com/downloads/details.aspx?familyid=ADEA09B4-481A -4908-8B77-0630AC679CAC&displaylang=en
Microsoft Word 2002 SP1
-
Microsoft Security Update for Word 2002 (KB917335)
http://www.microsoft.com/downloads/details.aspx?familyid=4CDE644B-BE05 -4680-B0EF-DF563095563C&displaylang=en
Microsoft Word Viewer 2003 0
-
Microsoft Security Update for Word Viewer 2003 (KB917346)
http://www.microsoft.com/downloads/details.aspx?familyid=6089B843-61FF -469F-A38B-BD4FFEFF0552&displaylang=en
Microsoft Word 2002
-
Microsoft Security Update for Word 2002 (KB917335)
http://www.microsoft.com/downloads/details.aspx?familyid=4CDE644B-BE05 -4680-B0EF-DF563095563C&displaylang=en
Microsoft Works Suite 2003
-
Microsoft Security Update for Word 2002 (KB917335)
http://www.microsoft.com/downloads/details.aspx?familyid=4CDE644B-BE05 -4680-B0EF-DF563095563C&displaylang=en
Microsoft Word 2002 SP3
-
Microsoft Security Update for Word 2002 (KB917335)
http://www.microsoft.com/downloads/details.aspx?familyid=4CDE644B-BE05 -4680-B0EF-DF563095563C&displaylang=en
Microsoft Works Suite 2002
-
Microsoft Security Update for Word 2002 (KB917335)
http://www.microsoft.com/downloads/details.aspx?familyid=4CDE644B-BE05 -4680-B0EF-DF563095563C&displaylang=en
Microsoft Works Suite 2000 0
-
Microsoft Security Update for Word 2000 (KB917345)
http://www.microsoft.com/downloads/details.aspx?familyid=507D97B5-8B20 -41B2-AE8B-27F2BF5198CD&displaylang=en
Microsoft Works Suite 2006 0
-
Microsoft Security Update for Word 2002 (KB917335)
http://www.microsoft.com/downloads/details.aspx?familyid=4CDE644B-BE05 -4680-B0EF-DF563095563C&displaylang=en
Microsoft Works Suite 2005 0
-
Microsoft Security Update for Word 2002 (KB917335)
http://www.microsoft.com/downloads/details.aspx?familyid=4CDE644B-BE05 -4680-B0EF-DF563095563C&displaylang=en
Microsoft Works Suite 2001
-
Microsoft Security Update for Word 2000 (KB917345)
http://www.microsoft.com/downloads/details.aspx?familyid=507D97B5-8B20 -41B2-AE8B-27F2BF5198CD&displaylang=en
Microsoft Works Suite 2004
-
Microsoft Security Update for Word 2002 (KB917335)
http://www.microsoft.com/downloads/details.aspx?familyid=4CDE644B-BE05 -4680-B0EF-DF563095563C&displaylang=en
References
Microsoft Word Malformed Object Pointer Remote Code Execution Vulnerability
References:
References:
- Backdoor.Ginwui (Symantec)
- Microsoft Security Advisory (919637) (Microsoft)
- Microsoft Security Bulletin MS06-027 (Microsoft)
- Technet Security (Microsoft)
- Trojan.Mdropper.H (Symantec)