Microsoft Office Smart Tag Remote Code Execution Vulnerability
BID:20320
Info
Microsoft Office Smart Tag Remote Code Execution Vulnerability
| Bugtraq ID: | 20320 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-3868 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 10 2006 12:00AM |
| Updated: | Sep 20 2007 12:00AM |
| Credit: | The original discoverer of this issue is currently unknown. |
| Vulnerable: |
Microsoft Visio 2002 SP2 Microsoft Visio 2002 SP1 Microsoft Project 2002 SP2 Microsoft Project 2002 SP1 Microsoft Project 2002 0 Microsoft Office XP SP3 Microsoft Office XP SP2 Microsoft Office XP SP1 Microsoft Office 2003 SP2 Microsoft Office 2003 SP1 |
| Not Vulnerable: | |
Discussion
Microsoft Office Smart Tag Remote Code Execution Vulnerability
Microsoft Office is prone to a remote code-execution vulnerability. This issue occurs when Office attempts to process malformed files.
An attacker could exploit this issue by enticing a victim to load a malicious Office file. If the vulnerability is successfully exploited, this could result in the execution of arbitrary code in the context of the currently logged-in user.
Microsoft Office is prone to a remote code-execution vulnerability. This issue occurs when Office attempts to process malformed files.
An attacker could exploit this issue by enticing a victim to load a malicious Office file. If the vulnerability is successfully exploited, this could result in the execution of arbitrary code in the context of the currently logged-in user.
Exploit / POC
Microsoft Office Smart Tag Remote Code Execution Vulnerability
Exploit code targeting this issue is reported to be circulating in the wild. The exploit obfuscates itself by using the ActiveX control CLSID:{0002E510-0000-0000-C000-000000000046} to imbed a malicious Office document in an HTML/JavaScript page.
Exploit code targeting this issue is reported to be circulating in the wild. The exploit obfuscates itself by using the ActiveX control CLSID:{0002E510-0000-0000-C000-000000000046} to imbed a malicious Office document in an HTML/JavaScript page.
Solution / Fix
Microsoft Office Smart Tag Remote Code Execution Vulnerability
Solution:
Microsoft has released a security advisory addressing this issue.
Microsoft Office XP SP3
Microsoft Office 2003 SP2
Solution:
Microsoft has released a security advisory addressing this issue.
Microsoft Office XP SP3
-
Microsoft Security Update for Office XP (KB923273)
http://www.microsoft.com/downloads/details.aspx?familyid=958EE063-D88D -4E45-8555-4D1C4730F5C8
Microsoft Office 2003 SP2
-
Microsoft Security Update for Office 2003 (KB923272)
http://www.microsoft.com/downloads/details.aspx?familyid=0D399F68-EC0D -4768-9846-B16B3DADF247
References
Microsoft Office Smart Tag Remote Code Execution Vulnerability
References:
References:
- JavaScript/HTML droppers as a targeted attack vector (Maarten Van Horenbeeck)
- Microsoft Word Homepage (Microsoft )
- Microsoft Security Advisory MS06-062 (Microsoft)