Microsoft Word CVE-2012-0183 RTF Data Handling Remote Memory Corruption Vulnerability
BID:53344
Info
Microsoft Word CVE-2012-0183 RTF Data Handling Remote Memory Corruption Vulnerability
| Bugtraq ID: | 53344 |
| Class: | Unknown |
| CVE: |
CVE-2012-0183 |
| Remote: | Yes |
| Local: | No |
| Published: | May 08 2012 12:00AM |
| Updated: | Nov 15 2012 07:20PM |
| Credit: | An anonymous researcher working with TippingPoint's Zero Day Initiative |
| Vulnerable: |
Microsoft Word 2007 SP3 Microsoft Word 2007 SP2 Microsoft Word 2007 SP1 Microsoft Word 2007 0 Microsoft Word 2003 SP3 Microsoft Word 2003 SP2 Microsoft Word 2003 SP1 Microsoft Office Compatibility Pack SP3 Microsoft Office Compatibility Pack SP2 Microsoft Office 2011 for Mac 0 Microsoft Office 2008 for Mac 0 |
| Not Vulnerable: | |
Discussion
Microsoft Word CVE-2012-0183 RTF Data Handling Remote Memory Corruption Vulnerability
Microsoft Word is prone to a remote memory-corruption vulnerability.
An attacker can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial-of-service conditions.
Microsoft Word is prone to a remote memory-corruption vulnerability.
An attacker can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial-of-service conditions.
Exploit / POC
Microsoft Word CVE-2012-0183 RTF Data Handling Remote Memory Corruption Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Word CVE-2012-0183 RTF Data Handling Remote Memory Corruption Vulnerability
Solution:
The vendor has released an advisory and updates. Please see the referenced advisory for details.
Microsoft Office Compatibility Pack SP2
Microsoft Word 2003 SP3
Microsoft Word 2007 SP3
Microsoft Office 2008 for Mac 0
Microsoft Word 2007 SP2
Microsoft Office 2011 for Mac 0
Microsoft Office Compatibility Pack SP3
Solution:
The vendor has released an advisory and updates. Please see the referenced advisory for details.
Microsoft Office Compatibility Pack SP2
-
Microsoft Security Update for Microsoft Office 2007 suites (KB2596880)
http://www.microsoft.com/downloads/details.aspx?familyid=80d5a86a-33b0 -4464-af76-0fe13bd07a5c
Microsoft Word 2003 SP3
-
Microsoft Security Update for Microsoft Office Word 2003 (KB2598332)
http://www.microsoft.com/downloads/details.aspx?familyid=9819899d-7f7f -4ddd-9fc8-816a57d2979e
Microsoft Word 2007 SP3
-
Microsoft Security Update for Microsoft Office Word 2007 (KB2596917)
http://www.microsoft.com/downloads/details.aspx?familyid=c6f79d01-8735 -4b0f-a50b-90cde3fba4ee
Microsoft Office 2008 for Mac 0
-
Microsoft Microsoft Office 2008 for Mac 12.3.3 Update
http://www.microsoft.com/downloads/details.aspx?familyid=8f85fc23-480e -4835-9ce5-0aa56702ef59
Microsoft Word 2007 SP2
-
Microsoft Security Update for Microsoft Office Word 2007 (KB2596917)
http://www.microsoft.com/downloads/details.aspx?familyid=c6f79d01-8735 -4b0f-a50b-90cde3fba4ee
Microsoft Office 2011 for Mac 0
-
Microsoft Microsoft Office 2011 14.2.2 Update
http://www.microsoft.com/downloads/details.aspx?familyid=5d88d3d4-89bd -44c3-9e5a-657998223e2f
Microsoft Office Compatibility Pack SP3
-
Microsoft Security Update for Microsoft Office 2007 suites (KB2596880)
http://www.microsoft.com/downloads/details.aspx?familyid=80d5a86a-33b0 -4464-af76-0fe13bd07a5c
References
Microsoft Word CVE-2012-0183 RTF Data Handling Remote Memory Corruption Vulnerability
References:
References:
- Microsoft Word Homepage (Microsoft )
- Microsoft Security Bulletin MS12-029 (Microsoft)