Auto-execution Of VBA code Vulnerability
BID:196
Info
Auto-execution Of VBA code Vulnerability
| Bugtraq ID: | 196 |
| Class: | Access Validation Error |
| CVE: |
CVE-1999-0354 |
| Remote: | No |
| Local: | No |
| Published: | Jan 27 1999 12:00AM |
| Updated: | Jul 11 2009 12:16AM |
| Credit: | This vulnerability was posted to NTBugtraq mailing list by Vesselin Bontchev <[email protected]> |
| Vulnerable: |
Microsoft Word 97 SR2 Microsoft Word 97 SR1 Microsoft Word 97 Microsoft Outlook 98 0 Microsoft Internet Explorer 5.0 for Windows NT 4 Microsoft Internet Explorer 5.0 for Windows 98 Microsoft Internet Explorer 4.0 for Windows NT 4 Microsoft Internet Explorer 4.0 for Windows 95 Microsoft Internet Explorer 4.0 |
| Not Vulnerable: | |
Discussion
Auto-execution Of VBA code Vulnerability
Similar to the Russian New Year's exploit, this vulnerability demonstrates the ability for malicious code to be executed on a web user's machine via the use of VBA code that may be executed upon opening or viewing a file.
Office97 applications may be configured to prompt the user before launching the VBA code. Unfortunately, the templates upon which Word documents are based DO NOT prompt the user upon opening VBA code.
Outlook documents in HTML code may be trojaned in a similar fashion.
IE4 and IE5 may also trigger the same VBA trojan if they are configured to automatically display Office documents form within the browser window.
Similar to the Russian New Year's exploit, this vulnerability demonstrates the ability for malicious code to be executed on a web user's machine via the use of VBA code that may be executed upon opening or viewing a file.
Office97 applications may be configured to prompt the user before launching the VBA code. Unfortunately, the templates upon which Word documents are based DO NOT prompt the user upon opening VBA code.
Outlook documents in HTML code may be trojaned in a similar fashion.
IE4 and IE5 may also trigger the same VBA trojan if they are configured to automatically display Office documents form within the browser window.
Exploit / POC
Auto-execution Of VBA code Vulnerability
see discussion
see discussion
Solution / Fix
Auto-execution Of VBA code Vulnerability
Solution:
Microsoft has released a patch for Word97:
http://officeupdate.microsoft.com/downloaddetails/wd97sp.htm
Microsoft has released an advisory on this vulnerability:
http://www.microsoft.com/security/bulletins/ms99-002.asp
Solution:
Microsoft has released a patch for Word97:
http://officeupdate.microsoft.com/downloaddetails/wd97sp.htm
Microsoft has released an advisory on this vulnerability:
http://www.microsoft.com/security/bulletins/ms99-002.asp
References
Auto-execution Of VBA code Vulnerability
References:
References: