Microsoft Office Publisher Invalid Memory Reference Remote Code Execution Vulnerability
BID:22702
Info
Microsoft Office Publisher Invalid Memory Reference Remote Code Execution Vulnerability
| Bugtraq ID: | 22702 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-1117 CVE-2007-1754 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 23 2007 12:00AM |
| Updated: | Jul 05 2016 09:38PM |
| Credit: | eEye Research is credited with the discovery of this vulnerability. |
| Vulnerable: |
Microsoft Publisher 2007 0 Microsoft Office 2007 0 |
| Not Vulnerable: | |
Discussion
Microsoft Office Publisher Invalid Memory Reference Remote Code Execution Vulnerability
Microsoft Office Publisher is prone to a remote code-execution vulnerability.
An attacker can exploit this issue by enticing an unsuspecting victim to open a maliciously crafted Publisher file.
Successful exploits may allow attackers to execute arbitrary code with privileges of the user running the application. This may facilitate a compromise of vulnerable computers.
Microsoft Office Publisher is prone to a remote code-execution vulnerability.
An attacker can exploit this issue by enticing an unsuspecting victim to open a maliciously crafted Publisher file.
Successful exploits may allow attackers to execute arbitrary code with privileges of the user running the application. This may facilitate a compromise of vulnerable computers.
Exploit / POC
Microsoft Office Publisher Invalid Memory Reference Remote Code Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Office Publisher Invalid Memory Reference Remote Code Execution Vulnerability
Solution:
Microsoft released an advisory and fixes to address this issue. Please see the references for more information.
Microsoft Publisher 2007 0
Solution:
Microsoft released an advisory and fixes to address this issue. Please see the references for more information.
Microsoft Publisher 2007 0
-
Microsoft Security Update for Microsoft Office Publisher 2007 (KB936646)
http://www.microsoft.com/downloads/details.aspx?FamilyId=25D272E7-F2DD -4342-92BE-7EBC2E770B44
References
Microsoft Office Publisher Invalid Memory Reference Remote Code Execution Vulnerability
References:
References:
- Microsoft Office Product Homepage (Microsoft)
- AD20070710 Microsoft Publisher 2007 Arbitrary Pointer Dereference (eEye Digital Security)
- EEYE: Microsoft Publisher 2007 Arbitrary Pointer Dereference (eEye Advisories)
- EEYEB-20070216 (eEye Research)
- Microsoft Security Bulletin MS07-037 - Vulnerability in Microsoft Office Publish (Microsoft)