Microsoft Office Malformed EPS Filter Remote Code Execution Vulnerability
BID:30595
Info
Microsoft Office Malformed EPS Filter Remote Code Execution Vulnerability
| Bugtraq ID: | 30595 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-3019 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 12 2008 12:00AM |
| Updated: | Aug 25 2008 03:05PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Microsoft Works 8.0 Microsoft Project 2002 SP1 Microsoft Project 2002 0 Microsoft Office XP SP3 Microsoft Office XP SP2 Microsoft Office XP SP1 Microsoft Office XP Microsoft Office Converter Pack 0 Microsoft Office 2003 SP2 Microsoft Office 2003 SP1 Microsoft Office 2003 0 Microsoft Office 2000 SP3 Microsoft Office 2000 SP1 Microsoft Office 2000 Microsoft Internet Explorer for Unix SP2 |
| Not Vulnerable: | |
Discussion
Microsoft Office Malformed EPS Filter Remote Code Execution Vulnerability
Microsoft Office is prone to a remote code-execution vulnerability.
An attacker could exploit this issue by enticing a victim to open a malicious EPS (Encapsulated PostScript) file.
Successfully exploiting this issue would allow the attacker to execute arbitrary code in the context of the currently logged-in user.
Microsoft Office is prone to a remote code-execution vulnerability.
An attacker could exploit this issue by enticing a victim to open a malicious EPS (Encapsulated PostScript) file.
Successfully exploiting this issue would allow the attacker to execute arbitrary code in the context of the currently logged-in user.
Exploit / POC
Microsoft Office Malformed EPS Filter Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Office Malformed EPS Filter Remote Code Execution Vulnerability
Solution:
The vendor has released an advisory and updates. Please see the references for more information.
Microsoft Project 2002 SP1
Microsoft Office XP SP3
Microsoft Office 2003 SP2
Microsoft Office Converter Pack 0
Microsoft Office 2000 SP3
Solution:
The vendor has released an advisory and updates. Please see the references for more information.
Microsoft Project 2002 SP1
-
Microsoft Security Update for Microsoft Office XP (KB921596)
http://www.microsoft.com/downloads/details.aspx?familyid=bf566ce6-23da -45e5-9c2b-c47331d30e79
Microsoft Office XP SP3
-
Microsoft Security Update for Microsoft Office XP (KB921596)
http://www.microsoft.com/downloads/details.aspx?familyid=bf566ce6-23da -45e5-9c2b-c47331d30e79
Microsoft Office 2003 SP2
-
Microsoft Security Update for Microsoft Office 2003 (KB921598)
http://www.microsoft.com/downloads/details.aspx?familyid=e0df2f6e-1102 -461d-829f-5f3e2d7eb4b3
Microsoft Office Converter Pack 0
-
Microsoft Security Update for Microsoft Office 2003 File Converter Pack (KB925256)
http://www.microsoft.com/downloads/details.aspx?familyid=199b08c7-6d79 -4930-8f0c-31034629c485
Microsoft Office 2000 SP3
-
Microsoft Security Update for Microsoft Office 2000 (KB921595)
http://www.microsoft.com/downloads/details.aspx?familyid=3ab323ec-9f92 -453c-b7c7-9a95a9efcaea
References
Microsoft Office Malformed EPS Filter Remote Code Execution Vulnerability
References:
References:
- Microsoft Office Product Homepage (Microsoft)
- Microsoft Security Bulletin MS08-044 (Microsoft)