Microsoft Word HTML Linked Object Remote Memory Corruption Vulnerability
BID:42130
Info
Microsoft Word HTML Linked Object Remote Memory Corruption Vulnerability
| Bugtraq ID: | 42130 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2010-1903 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 10 2010 12:00AM |
| Updated: | Aug 11 2010 08:04PM |
| Credit: | Rodrigo Rubira Branco of the Check Point IPS Research Team |
| Vulnerable: |
Microsoft Word 2003 SP3 Microsoft Word 2003 SP2 Microsoft Word 2003 SP1 Microsoft Word 2002 SP3 Microsoft Word 2002 SP2 Microsoft Word 2002 SP1 |
| Not Vulnerable: | |
Discussion
Microsoft Word HTML Linked Object Remote Memory Corruption Vulnerability
Microsoft Word is prone to a remote memory-corruption vulnerability because it fails to properly allocate heap-based memory.
An attacker can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial-of-service conditions.
Microsoft Word is prone to a remote memory-corruption vulnerability because it fails to properly allocate heap-based memory.
An attacker can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial-of-service conditions.
Exploit / POC
Microsoft Word HTML Linked Object Remote Memory Corruption Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Word HTML Linked Object Remote Memory Corruption Vulnerability
Solution:
The vendor has released an advisory and updates. Please see the referenced advisory for details.
Microsoft Word 2003 SP3
Microsoft Word 2002 SP3
Solution:
The vendor has released an advisory and updates. Please see the referenced advisory for details.
Microsoft Word 2003 SP3
-
Microsoft Security Update for Microsoft Office Word 2003 (KB2251399)
http://www.microsoft.com/downloads/details.aspx?familyid=4360bcec-0731 -4d4a-89eb-7d28a4607f06
Microsoft Word 2002 SP3
-
Microsoft Security Update for Microsoft Word 2002 (KB2251389)
http://www.microsoft.com/downloads/details.aspx?familyid=978eb887-25b6 -4dde-a2ec-d2d1e7f1a434
References
Microsoft Word HTML Linked Object Remote Memory Corruption Vulnerability
References:
References:
- Microsoft Office Word HTML Linked Objects Memory Corruption Vulnerability - CVE- (Full Disclosure)
- Microsoft Word Homepage (Microsoft )
- ZDI-10-151: Microsoft Office Word 2007 plcffldMom Parsing Remote Code Execution (ZDI Disclosures
) - Microsoft Security Bulletin MS10-056 (Microsoft)
- ZDI-10-151 Microsoft Office Word 2007 plcffldMom Parsing Remote Code Execution V (Zero Day Initiative)