Microsoft Word Malformed String Remote Code Execution Vulnerability
BID:20341
Info
Microsoft Word Malformed String Remote Code Execution Vulnerability
| Bugtraq ID: | 20341 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-3647 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 10 2006 12:00AM |
| Updated: | Oct 13 2006 04:09PM |
| Credit: | Chen Xiaobo of McAfee Avert Labs is credited with the discovery of this vulnerability. |
| Vulnerable: |
Microsoft Works Suite 2006 0 Microsoft Works Suite 2005 0 Microsoft Works Suite 2004 Microsoft Word 2003 Microsoft Word 2002 SP3 Microsoft Word 2002 SP2 Microsoft Word 2002 SP1 Microsoft Word 2002 Microsoft Word 2000 SR1a Microsoft Word 2000 SR1 Microsoft Word 2000 SP3 Microsoft Word 2000 SP2 Microsoft Word 2000 Microsoft Office XP SP3 Microsoft Office XP SP2 Microsoft Office XP SP1 Microsoft Office XP Microsoft Office X for Mac 0 Microsoft Office 2004 for Mac 0 Microsoft Office 2003 SP2 Microsoft Office 2003 SP1 Microsoft Office 2003 0 Microsoft Office 2000 SP3 Microsoft Office 2000 SP1 Microsoft Office 2000 Microsoft Internet Explorer for Unix SP2 |
| Not Vulnerable: | |
Discussion
Microsoft Word Malformed String Remote Code Execution Vulnerability
Microsoft Word is prone to a remote code-execution vulnerability.
An attacker could exploit this issue by enticing a victim to load a malicious Word file. If the vulnerability is successfully exploited, this could result in the execution of arbitrary code in the context of the currently logged-in user.
Microsoft Word is prone to a remote code-execution vulnerability.
An attacker could exploit this issue by enticing a victim to load a malicious Word file. If the vulnerability is successfully exploited, this could result in the execution of arbitrary code in the context of the currently logged-in user.
Exploit / POC
Microsoft Word Malformed String Remote Code Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Microsoft Word Malformed String Remote Code Execution Vulnerability
Solution:
Microsoft has released a security advisory addressing this issue.
Microsoft Office XP SP3
Microsoft Office 2003 SP2
Microsoft Works Suite 2005 0
Microsoft Office 2000 SP3
Microsoft Works Suite 2004
Microsoft Office 2003 SP1
Microsoft Works Suite 2006 0
Solution:
Microsoft has released a security advisory addressing this issue.
Microsoft Office XP SP3
-
Microsoft Security Update for Word 2002 (KB920817)
http://www.microsoft.com/downloads/details.aspx?familyid=5652303E-04B3 -4713-AF2E-2C8D2450468D&displaylang=en
Microsoft Office 2003 SP2
-
Microsoft Security Update for Word 2003 (KB923094)
http://www.microsoft.com/downloads/details.aspx?familyid=30C516EB-BD63 -4248-A34D-47AF7E9EA55A&displaylang=en
Microsoft Works Suite 2005 0
-
Microsoft Security Update for Word 2002 (KB920817)
http://www.microsoft.com/downloads/details.aspx?familyid=5652303E-04B3 -4713-AF2E-2C8D2450468D&displaylang=en
Microsoft Office 2000 SP3
-
Microsoft Security Update for Office 2000 (KB923274)
http://www.microsoft.com/downloads/details.aspx?familyid=E0C7E1E4-7859 -4C7E-898E-1CF05014885B&displaylang=en
Microsoft Works Suite 2004
-
Microsoft Security Update for Word 2002 (KB920817)
http://www.microsoft.com/downloads/details.aspx?familyid=5652303E-04B3 -4713-AF2E-2C8D2450468D&displaylang=en
Microsoft Office 2003 SP1
-
Microsoft Security Update for Word 2003 (KB923094)
http://www.microsoft.com/downloads/details.aspx?familyid=30C516EB-BD63 -4248-A34D-47AF7E9EA55A&displaylang=en
Microsoft Works Suite 2006 0
-
Microsoft Security Update for Word 2002 (KB920817)
http://www.microsoft.com/downloads/details.aspx?familyid=5652303E-04B3 -4713-AF2E-2C8D2450468D&displaylang=en
References
Microsoft Word Malformed String Remote Code Execution Vulnerability
References:
References: