Microsoft Works File Converter Section Length Header Remote Heap Overflow Vulnerability
BID:27657
Info
Microsoft Works File Converter Section Length Header Remote Heap Overflow Vulnerability
| Bugtraq ID: | 27657 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-0216 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 12 2008 12:00AM |
| Updated: | Feb 14 2008 10:15PM |
| Credit: | Damian Put working with VeriSign iDefense VCP is credited with the discovery of this issue. |
| Vulnerable: |
Microsoft Works Suite 2005 0 Microsoft Works 8.0 Microsoft Office 2003 SP3 Microsoft Office 2003 SP2 |
| Not Vulnerable: |
Microsoft Works Suite 2006 0 Microsoft Works 9.0 Microsoft Works 8.5 Microsoft Office XP SP3 Microsoft Office XP SP2 Microsoft Office XP SP1 Microsoft Office XP Microsoft Office 2007 0 Microsoft Office 2000 SP3 Microsoft Office 2000 SP1 Microsoft Office 2000 Microsoft Internet Explorer for Unix SP2 |
Discussion
Microsoft Works File Converter Section Length Header Remote Heap Overflow Vulnerability
Microsoft Works File Converter is prone to a remote heap-overflow vulnerability because it fails to adequately validate user-supplied input.
An attacker could exploit this issue by enticing a victim to open a malicious '.wps' file.
Successfully exploiting this issue would allow the attacker to execute arbitrary code in the context of the currently logged-in user.
Microsoft Works File Converter is prone to a remote heap-overflow vulnerability because it fails to adequately validate user-supplied input.
An attacker could exploit this issue by enticing a victim to open a malicious '.wps' file.
Successfully exploiting this issue would allow the attacker to execute arbitrary code in the context of the currently logged-in user.
Exploit / POC
Microsoft Works File Converter Section Length Header Remote Heap Overflow Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Microsoft Works File Converter Section Length Header Remote Heap Overflow Vulnerability
Solution:
The vendor released an advisory and updates to address this issue. Please see the references for more information.
Microsoft Office 2003 SP2
Solution:
The vendor released an advisory and updates to address this issue. Please see the references for more information.
Microsoft Office 2003 SP2
-
Microsoft office2003-KB943973-FullFile-ENU.exe
http://www.microsoft.com/downloads/details.aspx?FamilyID=30C9C3FE-FB85 -43D9-BBC3-0B30D3A20286&displaylang=en
References
Microsoft Works File Converter Section Length Header Remote Heap Overflow Vulnerability
References:
References:
- Microsoft Works Homepage (Microsoft )
- iDefense Security Advisory 02.12.08: Microsoft Office Works Converter Heap Over (iDefense Labs
) - Microsoft Office Works Converter Heap Overflow Vulnerability (iDefense)
- Microsoft Security Bulletin MS08-011 (Microsoft)