Microsoft Publisher Invalid Memory Reference Remote Code Execution Vulnerability
BID:27739
Info
Microsoft Publisher Invalid Memory Reference Remote Code Execution Vulnerability
| Bugtraq ID: | 27739 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-0102 CVE-2008-0102 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 12 2008 12:00AM |
| Updated: | Jul 05 2016 09:38PM |
| Credit: | Bing Liu of Fortinet Security Research and Piotr Bania are credited with the discovery of this vulnerability. |
| Vulnerable: |
Microsoft Publisher 2003 SP2 Microsoft Publisher 2003 Microsoft Publisher 2002 SP3 Microsoft Publisher 2002 Microsoft Publisher 2000 SP3 Microsoft Publisher 2000 |
| Not Vulnerable: |
Microsoft Publisher 2003 SP3 |
Discussion
Microsoft Publisher Invalid Memory Reference Remote Code Execution Vulnerability
Microsoft Publisher is prone to a remote code-execution vulnerability.
An attacker could exploit this issue by enticing a victim to open a malicious Publisher file.
Successfully exploiting this issue would allow the attacker to execute arbitrary code in the context of the currently logged-in user.
Microsoft Publisher is prone to a remote code-execution vulnerability.
An attacker could exploit this issue by enticing a victim to open a malicious Publisher file.
Successfully exploiting this issue would allow the attacker to execute arbitrary code in the context of the currently logged-in user.
Exploit / POC
Microsoft Publisher Invalid Memory Reference Remote Code Execution Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Publisher Invalid Memory Reference Remote Code Execution Vulnerability
Solution:
The vendor released an advisory and updates to address this issue. Please see the references for more information.
Microsoft Publisher 2003
Microsoft Publisher 2000
Microsoft Publisher 2000 SP3
Microsoft Publisher 2002
Microsoft Publisher 2002 SP3
Microsoft Publisher 2003 SP2
Solution:
The vendor released an advisory and updates to address this issue. Please see the references for more information.
Microsoft Publisher 2003
-
Microsoft Security Update for Microsoft Office Publisher 2003 (KB946254)
http://www.microsoft.com/downloads/details.aspx?FamilyId=7078B952-09F6 -4C47-8C05-40667E1F1C3B
Microsoft Publisher 2000
-
Microsoft Security Update for Publisher 2000 (KB946255)
http://www.microsoft.com/downloads/details.aspx?FamilyId=D8B085FB-858F -4C7E-96DE-EDFF8F49D62A
Microsoft Publisher 2000 SP3
-
Microsoft Security Update for Publisher 2000 (KB946255)
http://www.microsoft.com/downloads/details.aspx?FamilyId=D8B085FB-858F -4C7E-96DE-EDFF8F49D62A
Microsoft Publisher 2002
-
Microsoft Security Update for Microsoft Publisher 2002 (KB946216)
http://www.microsoft.com/downloads/details.aspx?FamilyId=1135C63A-6CE7 -4051-81BA-BFBBA8D857FB
Microsoft Publisher 2002 SP3
-
Microsoft Security Update for Microsoft Publisher 2002 (KB946216)
http://www.microsoft.com/downloads/details.aspx?FamilyId=1135C63A-6CE7 -4051-81BA-BFBBA8D857FB
Microsoft Publisher 2003 SP2
-
Microsoft Security Update for Microsoft Office Publisher 2003 (KB946254)
http://www.microsoft.com/downloads/details.aspx?FamilyId=7078B952-09F6 -4C47-8C05-40667E1F1C3B
References
Microsoft Publisher Invalid Memory Reference Remote Code Execution Vulnerability
References:
References:
- Publisher Homepage (Microsoft)
- Microsoft Security Bulletin MS08-012 (Microsoft)