Microsoft Office Works File Converter (CVE-2012-0177) Heap Based Buffer Overflow Vulnerability
BID:52867
Info
Microsoft Office Works File Converter (CVE-2012-0177) Heap Based Buffer Overflow Vulnerability
| Bugtraq ID: | 52867 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2012-0177 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 10 2012 12:00AM |
| Updated: | Apr 10 2012 12:00AM |
| Credit: | Shaun Colley of IOActive, Ltd. |
| Vulnerable: |
Microsoft Works 6�??9 File Converter 0 Microsoft Works 9.0 Microsoft Office 2007 SP2 Microsoft Office 2007 SP1 Microsoft Office 2007 0 |
| Not Vulnerable: | |
Discussion
Microsoft Office Works File Converter (CVE-2012-0177) Heap Based Buffer Overflow Vulnerability
Microsoft Office is prone to a remote heap-based buffer-overflow vulnerability because the software fails to perform adequate boundary-checks on user-supplied data.
An attacker can exploit this issue by enticing an unsuspecting user into opening a specially crafted '.wps' file.
Successfully exploiting this issue allows attackers to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts may result in a denial-of-service condition.
Microsoft Office is prone to a remote heap-based buffer-overflow vulnerability because the software fails to perform adequate boundary-checks on user-supplied data.
An attacker can exploit this issue by enticing an unsuspecting user into opening a specially crafted '.wps' file.
Successfully exploiting this issue allows attackers to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts may result in a denial-of-service condition.
Exploit / POC
Microsoft Office Works File Converter (CVE-2012-0177) Heap Based Buffer Overflow Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Office Works File Converter (CVE-2012-0177) Heap Based Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for more information.
Microsoft Works 6�??9 File Converter 0
Microsoft Works 9.0
Solution:
Updates are available. Please see the references for more information.
Microsoft Works 6�??9 File Converter 0
-
Microsoft Security Update for Microsoft Works 6-9 Converter (KB2680326)
http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=29 330
Microsoft Works 9.0
-
Microsoft Security Update for Microsoft Works 9 (KB2680317)
http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=29 346
References
Microsoft Office Works File Converter (CVE-2012-0177) Heap Based Buffer Overflow Vulnerability
References:
References:
- Microsoft Office Product Homepage (Microsoft)
- Microsoft Security Bulletin MS12-028 - Important (Microsoft)