Microsoft Office CDO Protocol Cross Site Scripting Vulnerability
BID:31693
Info
Microsoft Office CDO Protocol Cross Site Scripting Vulnerability
| Bugtraq ID: | 31693 |
| Class: | Design Error |
| CVE: |
CVE-2008-4020 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 14 2008 12:00AM |
| Updated: | Oct 14 2008 06:07PM |
| Credit: | This issue was privately reported to Microsoft. |
| Vulnerable: |
Microsoft Office XP SP3 |
| Not Vulnerable: | |
Discussion
Microsoft Office CDO Protocol Cross Site Scripting Vulnerability
Microsoft Office is prone to a cross-site scripting vulnerability that arises because the software fails to handle specially crafted CDO protocol URIs in a proper manner.
Successfully exploiting this issue may allow an attacker to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Office XP Service Pack 3 is vulnerable.
Microsoft Office is prone to a cross-site scripting vulnerability that arises because the software fails to handle specially crafted CDO protocol URIs in a proper manner.
Successfully exploiting this issue may allow an attacker to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Office XP Service Pack 3 is vulnerable.
Exploit / POC
Microsoft Office CDO Protocol Cross Site Scripting Vulnerability
An attacker can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
An attacker can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
Solution / Fix
Microsoft Office CDO Protocol Cross Site Scripting Vulnerability
Solution:
The vendor released an advisory along with fixes to address this issue. Please see the references for more information.
Microsoft Office XP SP3
Solution:
The vendor released an advisory along with fixes to address this issue. Please see the references for more information.
Microsoft Office XP SP3
-
Microsoft Security Update for Office XP (KB956464)
http://www.microsoft.com/downloads/details.aspx?familyid=b1aee2d5-bfa0 -40e3-91b6-98bf65524e8c&displaylang=en
References
Microsoft Office CDO Protocol Cross Site Scripting Vulnerability
References:
References:
- Microsoft Security Bulletin MS08-056 (Microsoft)
- Microsoft Windows Homepage (Microsoft )