Microsoft Windows OLE Property CVE-2011-3400 Remote Code Execution Vulnerability
BID:50977
Info
Microsoft Windows OLE Property CVE-2011-3400 Remote Code Execution Vulnerability
| Bugtraq ID: | 50977 |
| Class: | Unknown |
| CVE: |
CVE-2011-3400 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 13 2011 12:00AM |
| Updated: | Jun 06 2012 05:30PM |
| Credit: | Luigi Auriemma |
| Vulnerable: |
Microsoft Windows XP Tablet PC Edition SP3 Microsoft Windows XP Professional x64 Edition SP2 Microsoft Windows XP Professional SP3 Microsoft Windows XP Media Center Edition SP3 Microsoft Windows XP Home SP3 Microsoft Windows XP Embedded SP3 Microsoft Windows Server 2003 x64 SP2 Microsoft Windows Server 2003 Web Edition SP2 Microsoft Windows Server 2003 Standard Edition SP2 Microsoft Windows Server 2003 Itanium SP2 Microsoft Windows Server 2003 Enterprise x64 Edition SP2 Microsoft Windows Server 2003 Enterprise Edition Itanium Sp2 Itanium Microsoft Windows Server 2003 Datacenter x64 Edition SP2 Microsoft Windows Server 2003 Datacenter Edition Itanium SP1 Beta 1 Microsoft Windows Server 2003 Sp2 X64 Microsoft Windows Server 2003 Sp2 Storage Microsoft Windows Server 2003 Sp2 Enterprise Microsoft Windows Server 2003 Sp2 Datacenter Microsoft Windows Server 2003 Sp2 Compute Cluster Microsoft Windows Server 2003 SP2 |
| Not Vulnerable: | |
Discussion
Microsoft Windows OLE Property CVE-2011-3400 Remote Code Execution Vulnerability
Microsoft Windows is prone to a remote code-execution vulnerability.
Attackers can exploit this issue by enticing an unsuspecting user to open a specially crafted file.
Successful exploits can allow attackers to execute arbitrary code with the privileges of the user running the application. Failed exploit attempts may result in a denial-of-service condition.
Microsoft Windows is prone to a remote code-execution vulnerability.
Attackers can exploit this issue by enticing an unsuspecting user to open a specially crafted file.
Successful exploits can allow attackers to execute arbitrary code with the privileges of the user running the application. Failed exploit attempts may result in a denial-of-service condition.
Exploit / POC
Microsoft Windows OLE Property CVE-2011-3400 Remote Code Execution Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
Microsoft Windows OLE Property CVE-2011-3400 Remote Code Execution Vulnerability
Solution:
Vendor updates are available. Please see the references for details.
Microsoft Windows Server 2003 Itanium SP2
Microsoft Windows XP Media Center Edition SP3
Microsoft Windows Server 2003 Web Edition SP2
Microsoft Windows XP Home SP3
Microsoft Windows XP Professional x64 Edition SP2
Microsoft Windows Server 2003 SP2
Microsoft Windows Server 2003 x64 SP2
Microsoft Windows Server 2003 Datacenter x64 Edition SP2
Microsoft Windows Server 2003 Enterprise x64 Edition SP2
Microsoft Windows XP Tablet PC Edition SP3
Microsoft Windows Server 2003 Standard Edition SP2
Solution:
Vendor updates are available. Please see the references for details.
Microsoft Windows Server 2003 Itanium SP2
-
Microsoft Security Update for Windows Server 2003 for Itanium-based Systems (KB2624667)
http://www.microsoft.com/downloads/details.aspx?familyid=4cdde8a9-6d44 -41fa-82c0-a25404cdfbb5
Microsoft Windows XP Media Center Edition SP3
-
Microsoft Security Update for Windows XP (KB2624667)
http://www.microsoft.com/downloads/details.aspx?familyid=73531165-f299 -4b62-b738-52fca410eaae
Microsoft Windows Server 2003 Web Edition SP2
-
Microsoft Security Update for Windows Server 2003 (KB2624667)
http://www.microsoft.com/downloads/details.aspx?familyid=6b555040-1117 -4b06-a48c-02f0e1b686d8
Microsoft Windows XP Home SP3
-
Microsoft Security Update for Windows XP (KB2624667)
http://www.microsoft.com/downloads/details.aspx?familyid=73531165-f299 -4b62-b738-52fca410eaae
Microsoft Windows XP Professional x64 Edition SP2
-
Microsoft Security Update for Windows XP x64 Edition (KB2624667)
http://www.microsoft.com/downloads/details.aspx?familyid=a98bb7cf-9939 -4927-8d21-ccb3845e7cb7
Microsoft Windows Server 2003 SP2
-
Microsoft Security Update for Windows Server 2003 (KB2624667)
http://www.microsoft.com/downloads/details.aspx?familyid=6b555040-1117 -4b06-a48c-02f0e1b686d8
Microsoft Windows Server 2003 x64 SP2
-
Microsoft Security Update for Windows Server 2003 x64 Edition (KB2624667)
http://www.microsoft.com/downloads/details.aspx?familyid=eb17782c-f754 -42ab-905b-6f141df008c3
Microsoft Windows Server 2003 Datacenter x64 Edition SP2
-
Microsoft Security Update for Windows Server 2003 x64 Edition (KB2624667)
http://www.microsoft.com/downloads/details.aspx?familyid=eb17782c-f754 -42ab-905b-6f141df008c3
Microsoft Windows Server 2003 Enterprise x64 Edition SP2
-
Microsoft Security Update for Windows Server 2003 x64 Edition (KB2624667)
http://www.microsoft.com/downloads/details.aspx?familyid=eb17782c-f754 -42ab-905b-6f141df008c3
Microsoft Windows XP Tablet PC Edition SP3
-
Microsoft Security Update for Windows XP (KB2624667)
http://www.microsoft.com/downloads/details.aspx?familyid=73531165-f299 -4b62-b738-52fca410eaae
Microsoft Windows Server 2003 Standard Edition SP2
-
Microsoft Security Update for Windows Server 2003 (KB2624667)
http://www.microsoft.com/downloads/details.aspx?familyid=6b555040-1117 -4b06-a48c-02f0e1b686d8
References
Microsoft Windows OLE Property CVE-2011-3400 Remote Code Execution Vulnerability
References:
References:
- Microsoft Windows Homepage (Microsoft )
- Microsoft OLE CPropertyStorage::ReadMultiple Variant Type Confusion Vulnerabilit (Luigi Auriemma)
- Microsoft Security Bulletin MS11-093 (Microsoft)