Microsoft Office 'MSO.dll' Uninitialized Pointer (CVE-2011-1982) Remote Code Execution Vulnerability
BID:49513
Info
Microsoft Office 'MSO.dll' Uninitialized Pointer (CVE-2011-1982) Remote Code Execution Vulnerability
| Bugtraq ID: | 49513 |
| Class: | Design Error |
| CVE: |
CVE-2011-1982 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 13 2011 12:00AM |
| Updated: | Sep 13 2011 12:00AM |
| Credit: | David Warren of the CERT/CC. |
| Vulnerable: |
Microsoft Office 2010 (64-bit edition) SP1 Microsoft Office 2010 (64-bit edition) 0 Microsoft Office 2010 (32-bit edition) 0 Microsoft Office 2010 0 Microsoft Office 2010 (32-bit edition) SP1 Microsoft Office 2007 SP2 Microsoft Office 2007 SP1 Microsoft Office 2007 0 |
| Not Vulnerable: | |
Discussion
Microsoft Office 'MSO.dll' Uninitialized Pointer (CVE-2011-1982) Remote Code Execution Vulnerability
Microsoft Office is prone to a remote code-execution vulnerability.
Attackers can exploit this issue by enticing an unsuspecting user to open a specially crafted Word file.
Successful exploits can allow attackers to execute arbitrary code with the privileges of the user running the application. Failed exploit attempts will result in a denial-of-service condition.
Microsoft Office is prone to a remote code-execution vulnerability.
Attackers can exploit this issue by enticing an unsuspecting user to open a specially crafted Word file.
Successful exploits can allow attackers to execute arbitrary code with the privileges of the user running the application. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
Microsoft Office 'MSO.dll' Uninitialized Pointer (CVE-2011-1982) Remote Code Execution Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Office 'MSO.dll' Uninitialized Pointer (CVE-2011-1982) Remote Code Execution Vulnerability
Solution:
Vendor updates are available. Please see the references for details.
Microsoft Office 2010 (64-bit edition) SP1
Microsoft Office 2010 (64-bit edition) 0
Microsoft Office 2010 (32-bit edition) SP1
Microsoft Office 2010 (32-bit edition) 0
Microsoft Office 2007 SP2
Solution:
Vendor updates are available. Please see the references for details.
Microsoft Office 2010 (64-bit edition) SP1
-
Microsoft Security Update for Microsoft Office 2010 (KB2584066), 64-Bit Edition
http://www.microsoft.com/downloads/details.aspx?familyid=85360DC1-99E7 -4E3E-BE6F-3795E8A8122F
Microsoft Office 2010 (64-bit edition) 0
-
Microsoft Security Update for Microsoft Office 2010 (KB2584066), 64-Bit Edition
http://www.microsoft.com/downloads/details.aspx?familyid=85360DC1-99E7 -4E3E-BE6F-3795E8A8122F
Microsoft Office 2010 (32-bit edition) SP1
-
Microsoft Security Update for Microsoft Office 2010 (KB2584066), 32-Bit Edition
http://www.microsoft.com/downloads/details.aspx?familyid=3C8FD04A-9DF6 -4726-A9BC-811F49665981
Microsoft Office 2010 (32-bit edition) 0
-
Microsoft Security Update for Microsoft Office 2010 (KB2584066), 32-Bit Edition
http://www.microsoft.com/downloads/details.aspx?familyid=3C8FD04A-9DF6 -4726-A9BC-811F49665981
Microsoft Office 2007 SP2
-
Microsoft Security Update for Microsoft Office 2007 System (KB2584063)
http://www.microsoft.com/downloads/details.aspx?familyid=34BBEE95-0E83 -4705-8BFE-02E4FB22F8E7
References
Microsoft Office 'MSO.dll' Uninitialized Pointer (CVE-2011-1982) Remote Code Execution Vulnerability
References:
References:
- Microsoft Office Product Homepage (Microsoft)
- Microsoft Office uninitialized object pointer vulnerability (CERT)
- Microsoft Security Bulletin MS11-073 (Microsoft)