Microsoft Works File Converter Section Header Index Table Remote Code Execution Vulnerability
BID:27658
Info
Microsoft Works File Converter Section Header Index Table Remote Code Execution Vulnerability
| Bugtraq ID: | 27658 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-0105 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 12 2008 12:00AM |
| Updated: | Feb 12 2008 10:06PM |
| Credit: | IBM Internet Security Systems X-Force is credited with the discovery of this vulnerability |
| Vulnerable: |
Microsoft Works Suite 2005 0 Microsoft Works 8.0 Microsoft Office 2003 SP3 Microsoft Office 2003 SP2 |
| Not Vulnerable: |
Microsoft Works Suite 2006 0 Microsoft Works 9.0 Microsoft Works 8.5 Microsoft Office XP SP3 Microsoft Office XP SP2 Microsoft Office XP SP1 Microsoft Office XP Microsoft Office 2007 0 Microsoft Office 2000 SP3 Microsoft Office 2000 SP1 Microsoft Office 2000 Microsoft Internet Explorer for Unix SP2 |
Discussion
Microsoft Works File Converter Section Header Index Table Remote Code Execution Vulnerability
Microsoft Works File Converter is prone to a remote code-execution vulnerability because it fails to adequately validate user-supplied input.
An attacker could exploit this issue by enticing a victim to open a malicious '.wps' file.
Successfully exploiting this issue would allow the attacker to execute arbitrary code in the context of the currently logged-in user.
Microsoft Works File Converter is prone to a remote code-execution vulnerability because it fails to adequately validate user-supplied input.
An attacker could exploit this issue by enticing a victim to open a malicious '.wps' file.
Successfully exploiting this issue would allow the attacker to execute arbitrary code in the context of the currently logged-in user.
Exploit / POC
Microsoft Works File Converter Section Header Index Table Remote Code Execution Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Works File Converter Section Header Index Table Remote Code Execution Vulnerability
Solution:
The vendor released an advisory and updates to address this issue. Please see the references for more information.
Microsoft Office 2003 SP2
Solution:
The vendor released an advisory and updates to address this issue. Please see the references for more information.
Microsoft Office 2003 SP2
-
Microsoft office2003-KB943973-FullFile-ENU.exe
http://www.microsoft.com/downloads/details.aspx?FamilyID=30C9C3FE-FB85 -43D9-BBC3-0B30D3A20286&displaylang=en
References
Microsoft Works File Converter Section Header Index Table Remote Code Execution Vulnerability
References:
References:
- Microsoft Works Homepage (Microsoft )
- Microsoft Security Bulletin MS08-011 (Microsoft)