Microsoft Office Malformed String Parsing Code Execution Vulnerability
BID:18889
Info
Microsoft Office Malformed String Parsing Code Execution Vulnerability
| Bugtraq ID: | 18889 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-1540 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 11 2006 12:00AM |
| Updated: | Jul 12 2006 10:43PM |
| Credit: | Discovery is credited to Elia Florio of Symantec. |
| Vulnerable: |
Microsoft Visio 2002 Standard SP2 Microsoft Visio 2002 Professional SP2 Microsoft Visio 2002 SP2 Microsoft Visio 2002 SP1 Microsoft Visio 2002 Microsoft Project 2002 SP2 Microsoft Project 2002 SP1 Microsoft Project 2002 Microsoft Project 2000 SR1 Microsoft Project 2000 Microsoft Office XP SP3 Microsoft Office XP SP2 Microsoft Office XP SP1 Microsoft Office XP Microsoft Office X for Mac 0 Microsoft Office 2004 for Mac 0 Microsoft Office 2003 SP2 Microsoft Office 2003 SP1 Microsoft Office 2003 0 Microsoft Office 2000 Korean Version Microsoft Office 2000 Japanese Version Microsoft Office 2000 Chinese Version Microsoft Office 2000 SP3 Microsoft Office 2000 SP1 Microsoft Office 2000 Microsoft Internet Explorer for Unix SP2 |
| Not Vulnerable: | |
Discussion
Microsoft Office Malformed String Parsing Code Execution Vulnerability
Microsoft Office is prone to a code-execution vulnerability. This condition can occur when a malformed string within an Office file is parsed.
This vulnerability is located in a shared library used by multiple Office applications, potentially allowing many different attack vectors.
An attacker could exploit this issue by enticing a victim to load a malicious Office file. If the vulnerability is successfully exploited, this could result in the execution of arbitrary code in the context of the currently logged-in user.
This issue differs from the one described in BID 18912 (Microsoft Office String Parsing Remote Code Execution Vulnerability).
Microsoft Office is prone to a code-execution vulnerability. This condition can occur when a malformed string within an Office file is parsed.
This vulnerability is located in a shared library used by multiple Office applications, potentially allowing many different attack vectors.
An attacker could exploit this issue by enticing a victim to load a malicious Office file. If the vulnerability is successfully exploited, this could result in the execution of arbitrary code in the context of the currently logged-in user.
This issue differs from the one described in BID 18912 (Microsoft Office String Parsing Remote Code Execution Vulnerability).
Exploit / POC
Microsoft Office Malformed String Parsing Code Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Microsoft Office Malformed String Parsing Code Execution Vulnerability
Solution:
Microsoft has released a security advisory addressing this issue.
Microsoft Project 2000 SR1
Microsoft Project 2002 SP1
Microsoft Office XP SP3
Microsoft Office 2003 SP2
Microsoft Office 2000 SP3
Microsoft Project 2002 SP2
Microsoft Visio 2002 SP2
Solution:
Microsoft has released a security advisory addressing this issue.
Microsoft Project 2000 SR1
-
Microsoft Security Update for Project 2000 (KB917152)
http://www.microsoft.com/downloads/details.aspx?familyid=5C28E38A-F323 -4006-BEED-A00840CAFBCE
Microsoft Project 2002 SP1
-
Microsoft Security Update for Project 2002 (KB917150)
http://www.microsoft.com/downloads/details.aspx?familyid=BF9CBFA6-5E91 -4AA8-82C1-4C9A92A5B954
Microsoft Office XP SP3
-
Microsoft Security Update for Office XP (KB917150)
http://www.microsoft.com/downloads/details.aspx?familyid=266C287E-A773 -4D9C-9736-EEAFB34FF893
Microsoft Office 2003 SP2
-
Microsoft Security Update for Office 2003 (KB917151)
http://www.microsoft.com/downloads/details.aspx?familyid=1B11AC6B-4A78 -4A7B-995F-94738CAFE27F
Microsoft Office 2000 SP3
-
Microsoft Security Update for Office 2000 (KB917152)
http://www.microsoft.com/downloads/details.aspx?familyid=776FF379-0B9D -45D5-8B3C-CF9A4BD25DAE
Microsoft Project 2002 SP2
-
Microsoft Security Update for Project 2002 (KB917150)
http://www.microsoft.com/downloads/details.aspx?familyid=BF9CBFA6-5E91 -4AA8-82C1-4C9A92A5B954
Microsoft Visio 2002 SP2
-
Microsoft Security Update for Visio 2002 (KB917150)
http://www.microsoft.com/downloads/details.aspx?familyid=9F67D75A-B69D -4064-942C-F5515C920E6B
References
Microsoft Office Malformed String Parsing Code Execution Vulnerability
References:
References: