Microsoft Visual Basic for Applications Document Check Buffer Overflow Vulnerability
BID:19414
CVE-2006-3649 |Info
Microsoft Visual Basic for Applications Document Check Buffer Overflow Vulnerability
| Bugtraq ID: | 19414 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-3649 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 08 2006 12:00AM |
| Updated: | Jun 27 2007 03:28AM |
| Credit: | Ka Chun Leung of Symantec is credited with the discovery of this vulnerability. |
| Vulnerable: |
Nortel Networks Contact Center Manager Server 0 Nortel Networks Contact Center Manager Nortel Networks Contact Center Express Nortel Networks Contact Center - CCT 0 Nortel Networks Contact Center Microsoft Works Suite 2006 0 Microsoft Works Suite 2005 0 Microsoft Works Suite 2004 Microsoft Visual Basic for Applications SDK 6.4 Microsoft Visual Basic for Applications SDK 6.3 Microsoft Visual Basic for Applications SDK 6.2 Microsoft Visual Basic for Applications SDK 6.0 Microsoft Visio 2002 SP2 Microsoft Project 2002 SP1 Microsoft Project 2000 SR1 Microsoft Office XP SP3 Microsoft Office 2000 SP3 Microsoft Access 2000 SP3 |
| Not Vulnerable: |
Microsoft Office 2003 SP2 Microsoft Office 2003 SP1 |
Discussion
Microsoft Visual Basic for Applications Document Check Buffer Overflow Vulnerability
A vulnerability has been discovered in Microsoft Visual Basic for Applications. The vulnerability occurs due to insufficient bounds checking when checking the properties of malicious documents. As a result, a malformed document may be able to trigger a buffer-overflow within the affected application, effectively allowing for the execution of arbitrary code.
Microsoft Office, Access, Visio, Word, and Works are also reportedly attack vectors, since they employ VBA when handling certain document types. Email is another potential attack vector for this vulnerability, but merely opening an email would not trigger the issue; replying or forwarding the message could potentially trigger it.
Microsoft has reported that this issue is being exploited in the wild.
A vulnerability has been discovered in Microsoft Visual Basic for Applications. The vulnerability occurs due to insufficient bounds checking when checking the properties of malicious documents. As a result, a malformed document may be able to trigger a buffer-overflow within the affected application, effectively allowing for the execution of arbitrary code.
Microsoft Office, Access, Visio, Word, and Works are also reportedly attack vectors, since they employ VBA when handling certain document types. Email is another potential attack vector for this vulnerability, but merely opening an email would not trigger the issue; replying or forwarding the message could potentially trigger it.
Microsoft has reported that this issue is being exploited in the wild.
Exploit / POC
Microsoft Visual Basic for Applications Document Check Buffer Overflow Vulnerability
Although Microsoft has reported that this issue is being exploited in the wild, we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Although Microsoft has reported that this issue is being exploited in the wild, we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Microsoft Visual Basic for Applications Document Check Buffer Overflow Vulnerability
Solution:
Microsoft has released updates that address this issue.
Patches have been included for Office and other affected products. Please see the vendor advisory for more information.
Microsoft Project 2000 SR1
Microsoft Project 2002 SP1
Microsoft Office XP SP3
Microsoft Visual Basic for Applications SDK 6.2
Microsoft Visual Basic for Applications SDK 6.4
Microsoft Works Suite 2005 0
Microsoft Office 2000 SP3
Microsoft Works Suite 2004
Microsoft Visio 2002 SP2
Microsoft Visual Basic for Applications SDK 6.0
Microsoft Access 2000 SP3
Microsoft Works Suite 2006 0
Microsoft Visual Basic for Applications SDK 6.3
Solution:
Microsoft has released updates that address this issue.
Patches have been included for Office and other affected products. Please see the vendor advisory for more information.
Microsoft Project 2000 SR1
-
Microsoft Security Update for Project 2000 (KB920822)
Microsoft Project 2000 Service Release 1
http://www.microsoft.com/downloads/details.aspx?familyid=744DD25D-B9A7 -4E30-B64E-1C9BB0F87D90&displaylang=en
Microsoft Project 2002 SP1
-
Microsoft Security Update for Project 2002 (KB920821)
http://www.microsoft.com/downloads/details.aspx?familyid=62EF50AA-6061 -4185-9713-F8C31B195103&displaylang=en
Microsoft Office XP SP3
-
Microsoft Security Update for Office XP (KB920821)
http://www.microsoft.com/downloads/details.aspx?familyid=B26ADC3C-1DB8 -46FD-8381-B199EE351E7C&displaylang=en
Microsoft Visual Basic for Applications SDK 6.2
-
Microsoft Microsoft® Visual Basic® for Applications Update - KB923167
http://www.microsoft.com/downloads/details.aspx?familyid=424DF92A-3CC4 -4B72-B2F8-D45ED2A8F4B3&displaylang=en
Microsoft Visual Basic for Applications SDK 6.4
-
Microsoft Microsoft® Visual Basic® for Applications Update - KB923167
http://www.microsoft.com/downloads/details.aspx?familyid=424DF92A-3CC4 -4B72-B2F8-D45ED2A8F4B3&displaylang=en
Microsoft Works Suite 2005 0
-
Microsoft Security Update for Office XP (KB920821)
http://www.microsoft.com/downloads/details.aspx?familyid=B26ADC3C-1DB8 -46FD-8381-B199EE351E7C&displaylang=en
Microsoft Office 2000 SP3
-
Microsoft Security Update for Office 2000 (KB920822)
Microsoft Office 2000 Service Pack 3
http://www.microsoft.com/downloads/details.aspx?familyid=837A4FA9-FABC -4119-9AAF-2C8663029D2B&displaylang=en
Microsoft Works Suite 2004
-
Microsoft Security Update for Office XP (KB920821)
http://www.microsoft.com/downloads/details.aspx?familyid=B26ADC3C-1DB8 -46FD-8381-B199EE351E7C&displaylang=en
Microsoft Visio 2002 SP2
-
Microsoft Security Update for Visio 2002 (KB920821) - English
http://www.microsoft.com/downloads/details.aspx?familyid=43525B6A-58B7 -49C7-88D8-4983D1614A96&displaylang=en
Microsoft Visual Basic for Applications SDK 6.0
-
Microsoft Microsoft® Visual Basic® for Applications Update - KB923167
http://www.microsoft.com/downloads/details.aspx?familyid=424DF92A-3CC4 -4B72-B2F8-D45ED2A8F4B3&displaylang=en
Microsoft Access 2000 SP3
-
Microsoft Security Update for Access 2000 Runtime (KB920822)
http://www.microsoft.com/downloads/details.aspx?familyid=ED5A8C40-C592 -4299-AFB2-5F0F6E2B1DCD&displaylang=en
Microsoft Works Suite 2006 0
-
Microsoft Security Update for Office XP (KB920821)
http://www.microsoft.com/downloads/details.aspx?familyid=B26ADC3C-1DB8 -46FD-8381-B199EE351E7C&displaylang=en
Microsoft Visual Basic for Applications SDK 6.3
-
Microsoft Microsoft® Visual Basic® for Applications Update - KB923167
http://www.microsoft.com/downloads/details.aspx?familyid=424DF92A-3CC4 -4B72-B2F8-D45ED2A8F4B3&displaylang=en
References
Microsoft Visual Basic for Applications Document Check Buffer Overflow Vulnerability
References:
References: