RETIRED: Microsoft Jet Database Engine MDB File Parsing Remote Code Execution Vulnerability
BID:28398
Info
RETIRED: Microsoft Jet Database Engine MDB File Parsing Remote Code Execution Vulnerability
| Bugtraq ID: | 28398 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 22 2008 12:00AM |
| Updated: | Mar 24 2008 02:40PM |
| Credit: | The vendor disclosed this vulnerability. |
| Vulnerable: |
Microsoft Word 2007 SP1 Microsoft Word 2007 0 Microsoft Word 2003 SP3 Microsoft Word 2003 SP2 Microsoft Word 2002 SP3 Microsoft Word 2000 SP3 Microsoft JET 4.0 SP7 Microsoft JET 4.0 SP6 Microsoft JET 4.0 SP5 Microsoft JET 4.0 SP4 Microsoft JET 4.0 SP3 Microsoft JET 4.0 SP2 Microsoft JET 4.0 SP1 Microsoft JET 4.0 Microsoft JET 3.51 SP3 Microsoft JET 3.51 Microsoft JET 3.5 Microsoft JET 3.0 Microsoft JET 2.5 Microsoft JET 2.0 |
| Not Vulnerable: | |
Discussion
RETIRED: Microsoft Jet Database Engine MDB File Parsing Remote Code Execution Vulnerability
Microsoft Jet Database Engine is prone to a remote code-execution vulnerability.
Remote attackers can exploit this issue to execute arbitrary machine code in the context of a user running affected applications. Successful exploits will compromise the affected applications and possibly the underlying computer. Failed attacks will likely cause denial-of-service conditions.
This issue does not affect Windows Server 2003 Service Pack 2, Windows Vista, and Windows Vista Service Pack 1as they run a non-vulnerable version of the Jet Database Engine.
This issue does affect Microsoft Word 2000 Service Pack 3, Microsoft Word 2002 Service Pack 3, Microsoft Word 2003 Service Pack 2, Microsoft Word 2003 Service Pack 3, Microsoft Word 2007, and Microsoft Word 2007 Service Pack 1 on Microsoft Windows 2000, Windows XP, or Windows Server 2003 Service Pack 1.
NOTE: This issue is a duplicate of the vulnerability discussed in BID 26468 (Microsoft Jet DataBase Engine MDB File Parsing Remote Buffer Overflow Vulnerability).
Microsoft Jet Database Engine is prone to a remote code-execution vulnerability.
Remote attackers can exploit this issue to execute arbitrary machine code in the context of a user running affected applications. Successful exploits will compromise the affected applications and possibly the underlying computer. Failed attacks will likely cause denial-of-service conditions.
This issue does not affect Windows Server 2003 Service Pack 2, Windows Vista, and Windows Vista Service Pack 1as they run a non-vulnerable version of the Jet Database Engine.
This issue does affect Microsoft Word 2000 Service Pack 3, Microsoft Word 2002 Service Pack 3, Microsoft Word 2003 Service Pack 2, Microsoft Word 2003 Service Pack 3, Microsoft Word 2007, and Microsoft Word 2007 Service Pack 1 on Microsoft Windows 2000, Windows XP, or Windows Server 2003 Service Pack 1.
NOTE: This issue is a duplicate of the vulnerability discussed in BID 26468 (Microsoft Jet DataBase Engine MDB File Parsing Remote Buffer Overflow Vulnerability).
Exploit / POC
RETIRED: Microsoft Jet Database Engine MDB File Parsing Remote Code Execution Vulnerability
The vendor reports that there is evidence this issue is being exploited in the wild.
The vendor reports that there is evidence this issue is being exploited in the wild.
Solution / Fix
RETIRED: Microsoft Jet Database Engine MDB File Parsing Remote Code Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
RETIRED: Microsoft Jet Database Engine MDB File Parsing Remote Code Execution Vulnerability
References:
References: