Microsoft Office Web Components ActiveX Control Stack Buffer Overflow Code Execution Vulnerability
BID:35992
Info
Microsoft Office Web Components ActiveX Control Stack Buffer Overflow Code Execution Vulnerability
| Bugtraq ID: | 35992 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-1534 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 11 2009 12:00AM |
| Updated: | Apr 19 2013 02:40AM |
| Credit: | Sean Larsson of VeriSign iDefense Labs |
| Vulnerable: |
Microsoft Visual Studio .NET 2003 SP1 Microsoft Visual Studio .NET 2003 Microsoft Office XP Web Components SP3 Microsoft Office XP SP3 Microsoft Office XP SP2 Microsoft Office XP SP1 Microsoft Office XP Microsoft Office 2000 Web Components SP3 Microsoft Office 2000 SP3 Microsoft Office 2000 SP1 Microsoft Office 2000 Microsoft Internet Explorer for Unix SP2 Microsoft Biztalk Server 2002 Partner Edition 0 Microsoft BizTalk Server 2002 Enterprise Edition Microsoft BizTalk Server 2002 Developer Edition |
| Not Vulnerable: | |
Discussion
Microsoft Office Web Components ActiveX Control Stack Buffer Overflow Code Execution Vulnerability
The Microsoft Office Web Components ActiveX control is prone to a remote stack-based buffer-overflow vulnerability.
An attacker could exploit this issue by enticing a victim to visit a maliciously crafted webpage.
Successful exploits will allow the attacker to execute arbitrary code within the context of the affected application that uses the ActiveX control (typically Internet Explorer). Failed exploit attempts will result in a denial-of-service condition.
The Microsoft Office Web Components ActiveX control is prone to a remote stack-based buffer-overflow vulnerability.
An attacker could exploit this issue by enticing a victim to visit a maliciously crafted webpage.
Successful exploits will allow the attacker to execute arbitrary code within the context of the affected application that uses the ActiveX control (typically Internet Explorer). Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
Microsoft Office Web Components ActiveX Control Stack Buffer Overflow Code Execution Vulnerability
A commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available:
A commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available:
Solution / Fix
Microsoft Office Web Components ActiveX Control Stack Buffer Overflow Code Execution Vulnerability
Solution:
The vendor has released an advisory and fixes. Please see the references for details.
Microsoft Office 2000 Web Components SP3
Microsoft Office XP SP3
Microsoft Office XP Web Components SP3
Solution:
The vendor has released an advisory and fixes. Please see the references for details.
Microsoft Office 2000 Web Components SP3
-
Microsoft Security Update for Microsoft Office XP Web Components (KB947320)
http://www.microsoft.com/downloads/details.aspx?familyid=60e2e4e7-aa75 -441d-b6fc-7e850bf8e580
Microsoft Office XP SP3
-
Microsoft Security Update for Microsoft Office XP Web Components (KB947320)
http://www.microsoft.com/downloads/details.aspx?familyid=60e2e4e7-aa75 -441d-b6fc-7e850bf8e580
Microsoft Office XP Web Components SP3
-
Microsoft Security Update for Microsoft Office XP Web Components (KB947320)
http://www.microsoft.com/downloads/details.aspx?familyid=60e2e4e7-aa75 -441d-b6fc-7e850bf8e580
References
Microsoft Office Web Components ActiveX Control Stack Buffer Overflow Code Execution Vulnerability
References:
References:
- Microsoft Homepage (Microsoft)
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Microsoft Office Web Components 2000 Buffer Overflow Vulnerability (iDefense Labs)
- iDefense Security Advisory 08.11.09: Microsoft Office Web Components 2000 Buffer (iDefense Labs
) - Microsoft Security Bulletin MS09-043 (Microsoft)