Microsoft Office Embedded Shockwave Flash Object Security Bypass Weakness
BID:18583
CVE-2006-3014 |Info
Microsoft Office Embedded Shockwave Flash Object Security Bypass Weakness
| Bugtraq ID: | 18583 |
| Class: | Design Error |
| CVE: |
CVE-2006-3014 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 22 2006 12:00AM |
| Updated: | Jun 27 2007 10:18PM |
| Credit: | Discovered by Debasis Mohanty. |
| Vulnerable: |
Turbolinux Turbolinux FUJI Nortel Networks Self-Service Peri NT Server 0 Nortel Networks Self-Service Peri IVR 0 Nortel Networks Enterprise Network Management System Microsoft Office 2003 SP3 Microsoft Office 2003 SP2 Microsoft Office 2003 SP1 Microsoft Office 2003 0 Microsoft Excel 2003 SP2 Microsoft Excel 2003 SP1 Microsoft Excel 2003 |
| Not Vulnerable: | |
Discussion
Microsoft Office Embedded Shockwave Flash Object Security Bypass Weakness
Microsoft Office is prone to a weakness that may allow remote attackers to execute arbitrary script code contained in Shockwave Flash Objects without first requiring confirmation from users.
A successful attack may allow attackers to access sensitive information and potentially execute malicious commands on a vulnerable computer.
The researcher responsible for discovering this issue has indicated that it presents itself on Windows 2003 SP1, Windows XP Professional Edition SP1 and SP2 running Microsoft Office 2003, and Windows 2000 Professional running Microsoft Office 2003. Other versions may be vulnerable as well.
Microsoft Office is prone to a weakness that may allow remote attackers to execute arbitrary script code contained in Shockwave Flash Objects without first requiring confirmation from users.
A successful attack may allow attackers to access sensitive information and potentially execute malicious commands on a vulnerable computer.
The researcher responsible for discovering this issue has indicated that it presents itself on Windows 2003 SP1, Windows XP Professional Edition SP1 and SP2 running Microsoft Office 2003, and Windows 2000 Professional running Microsoft Office 2003. Other versions may be vulnerable as well.
Exploit / POC
Microsoft Office Embedded Shockwave Flash Object Security Bypass Weakness
A proof-of-concept exploit is available:
A proof-of-concept exploit is available:
Solution / Fix
Microsoft Office Embedded Shockwave Flash Object Security Bypass Weakness
Solution:
Microsoft has released an update to address this issue. Please see the references for further information.
Solution:
Microsoft has released an update to address this issue. Please see the references for further information.
References
Microsoft Office Embedded Shockwave Flash Object Security Bypass Weakness
References:
References:
- Microsoft Excel File Embedded Shockwave Flash Object Exploit (Debasis Mohanty)
- Microsoft Security Bulletin MS06-069 (Microsoft)
- NORTEL RESPONSE TO MICROSOFT SECURITY BULLETIN MS06-069 (Nortel Networks)