Microsoft Office Property Code Execution Vulnerability
BID:18911
CVE-2006-2389 |Info
Microsoft Office Property Code Execution Vulnerability
| Bugtraq ID: | 18911 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-2389 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 11 2006 12:00AM |
| Updated: | Sep 01 2010 06:37PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Microsoft Visio 2002 Standard SP2 Microsoft Visio 2002 Professional SP2 Microsoft Visio 2002 SP2 Microsoft Visio 2002 SP1 Microsoft Visio 2002 Microsoft Project 2002 SP2 Microsoft Project 2002 SP1 Microsoft Project 2002 Microsoft Project 2000 SR1 Microsoft Project 2000 Microsoft Office XP SP3 Microsoft Office XP SP2 Microsoft Office XP SP1 Microsoft Office XP Microsoft Office X for Mac 0 Microsoft Office 2004 for Mac 0 Microsoft Office 2003 SP2 Microsoft Office 2003 SP1 Microsoft Office 2003 0 Microsoft Office 2000 Korean Version Microsoft Office 2000 Japanese Version Microsoft Office 2000 Chinese Version Microsoft Office 2000 SP3 Microsoft Office 2000 SP1 Microsoft Office 2000 Microsoft Internet Explorer for Unix SP2 |
| Not Vulnerable: | |
Discussion
Microsoft Office Property Code Execution Vulnerability
Microsoft Office is prone to a code-execution vulnerability. This is due to a failure to handle exceptional conditions.
Successfully exploiting this issue allows attackers to corrupt process memory and to execute arbitrary code in the context of targeted users.
Microsoft Office is prone to a code-execution vulnerability. This is due to a failure to handle exceptional conditions.
Successfully exploiting this issue allows attackers to corrupt process memory and to execute arbitrary code in the context of targeted users.
Exploit / POC
Microsoft Office Property Code Execution Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
Microsoft Office Property Code Execution Vulnerability
Solution:
Microsoft has released a security advisory addressing this issue.
Microsoft Project 2000 SR1
Microsoft Project 2002 SP1
Microsoft Office XP SP3
Microsoft Office 2003 SP2
Microsoft Office 2000 SP3
Microsoft Project 2002 SP2
Microsoft Visio 2002 SP2
Solution:
Microsoft has released a security advisory addressing this issue.
Microsoft Project 2000 SR1
-
Microsoft Security Update for Project 2000 (KB917152)
http://www.microsoft.com/downloads/details.aspx?familyid=5C28E38A-F323 -4006-BEED-A00840CAFBCE
Microsoft Project 2002 SP1
-
Microsoft Security Update for Project 2002 (KB917150)
http://www.microsoft.com/downloads/details.aspx?familyid=BF9CBFA6-5E91 -4AA8-82C1-4C9A92A5B954
Microsoft Office XP SP3
-
Microsoft Security Update for Office XP (KB917150)
http://www.microsoft.com/downloads/details.aspx?familyid=266C287E-A773 -4D9C-9736-EEAFB34FF893
Microsoft Office 2003 SP2
-
Microsoft Security Update for Office 2003 (KB917151)
http://www.microsoft.com/downloads/details.aspx?familyid=1B11AC6B-4A78 -4A7B-995F-94738CAFE27F
Microsoft Office 2000 SP3
-
Microsoft Security Update for Office 2000 (KB917152)
http://www.microsoft.com/downloads/details.aspx?familyid=776FF379-0B9D -45D5-8B3C-CF9A4BD25DAE
Microsoft Project 2002 SP2
-
Microsoft Security Update for Project 2002 (KB917150)
http://www.microsoft.com/downloads/details.aspx?familyid=BF9CBFA6-5E91 -4AA8-82C1-4C9A92A5B954
Microsoft Visio 2002 SP2
-
Microsoft Security Update for Visio 2002 (KB917150)
http://www.microsoft.com/downloads/details.aspx?familyid=9F67D75A-B69D -4064-942C-F5515C920E6B
References
Microsoft Office Property Code Execution Vulnerability
References:
References: