Microsoft Word Workspace Memory Corruption Remote Code Execution Vulnerability
BID:25906
Info
Microsoft Word Workspace Memory Corruption Remote Code Execution Vulnerability
| Bugtraq ID: | 25906 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-3899 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 09 2007 12:00AM |
| Updated: | Oct 23 2007 09:37PM |
| Credit: | Kun-Hao Liu of Information & Communication Security Technology Center is credited with the discovery of this vulnerability |
| Vulnerable: |
Microsoft Word 2004 for Mac 0 Microsoft Word 2002 SP3 Microsoft Word 2002 SP2 Microsoft Word 2002 SP1 Microsoft Word 2002 Microsoft Word 2000 SR1a Microsoft Word 2000 SR1 Microsoft Word 2000 SP3 Microsoft Word 2000 SP2 |
| Not Vulnerable: | |
Discussion
Microsoft Word Workspace Memory Corruption Remote Code Execution Vulnerability
Microsoft Word is prone to a remote code-execution vulnerability.
An attacker could exploit this issue by enticing a victim to open a malicious Word file.
Successfully exploiting this issue would allow the attacker to execute arbitrary code in the context of the currently logged-in user.
NOTE: Successful exploits of this issue may be hampered because Microsoft Office 2007 and Office 2003 SP3 will not open some older Office file formats, including Office for Macintosh documents. Exploits of this issue involve the Macintosh file format.
Microsoft Word is prone to a remote code-execution vulnerability.
An attacker could exploit this issue by enticing a victim to open a malicious Word file.
Successfully exploiting this issue would allow the attacker to execute arbitrary code in the context of the currently logged-in user.
NOTE: Successful exploits of this issue may be hampered because Microsoft Office 2007 and Office 2003 SP3 will not open some older Office file formats, including Office for Macintosh documents. Exploits of this issue involve the Macintosh file format.
Exploit / POC
Microsoft Word Workspace Memory Corruption Remote Code Execution Vulnerability
This issue is being actively exploited in the wild. Exploits of this issue are detected as Trojan.Mdropper.Z.
This issue is being actively exploited in the wild. Exploits of this issue are detected as Trojan.Mdropper.Z.
Solution / Fix
Microsoft Word Workspace Memory Corruption Remote Code Execution Vulnerability
Solution:
The vendor released an advisory and updates to address this issue. Please see the references for more information.
NOTE (October 17, 2007): Microsoft has released further information regarding the update. After the update is applied, Word will still exit unexpectedly when the user opens a malformed document, but the vulnerability is no longer present so exploitation does not occur in such a case. The vendor has also provided information regarding stability issues stemming from the update. Please see MS07-060 for details.
Microsoft Word 2004 for Mac 0
Microsoft Word 2000 SP3
Microsoft Word 2002 SP3
Solution:
The vendor released an advisory and updates to address this issue. Please see the references for more information.
NOTE (October 17, 2007): Microsoft has released further information regarding the update. After the update is applied, Word will still exit unexpectedly when the user opens a malformed document, but the vulnerability is no longer present so exploitation does not occur in such a case. The vendor has also provided information regarding stability issues stemming from the update. Please see MS07-060 for details.
Microsoft Word 2004 for Mac 0
-
Microsoft Microsoft Office 2004 for Mac 11.3.8 Update
http://download.microsoft.com/download/8/1/1http://www.microsoft.com/m ac/downloads.aspx?pid=download&location=/mac/download/Office2004/Offic e2004_1138.xml&secid=4&ssid=38&flgnosysreq=True/811D792C-E8F2-44EB-A25 C-167FB828405B/Office2004-1138UpdateEN.dmg
Microsoft Word 2000 SP3
-
Microsoft Security Update for Word 2000 (KB942669)
http://www.microsoft.com/downloads/details.aspx?FamilyId=8B3072FB-5933 -47F7-A498-13A93E268E57&displaylang=en
Microsoft Word 2002 SP3
-
Microsoft Security Update for Word 2002 (KB942670)
http://www.microsoft.com/downloads/details.aspx?FamilyId=D6B787BB-03FF -4F67-8B69-6011FB18BA75
References
Microsoft Word Workspace Memory Corruption Remote Code Execution Vulnerability
References:
References:
- Microsoft Word Homepage (Microsoft )
- Microsoft Security Bulletin MS07-060 (Microsoft)