Microsoft Office XP/Internet Explorer OWC File Creation Vulnerability
BID:5359
Info
Microsoft Office XP/Internet Explorer OWC File Creation Vulnerability
Bugtraq ID:
5359
Class:
Design Error
CVE:
Remote:
Yes
Local:
No
Published:
Jul 30 2002 12:00AM
Updated:
Jul 30 2002 12:00AM
Credit:
Announced by Georgi Guninski.
Vulnerable:
Microsoft Office XP
-
Microsoft Windows 2000 Professional SP2
-
Microsoft Windows 2000 Professional SP1
-
Microsoft Windows 2000 Professional
-
Microsoft Windows 98
-
Microsoft Windows ME
-
Microsoft Windows NT Workstation 4.0 SP6a
-
Microsoft Windows NT Workstation 4.0 SP6
-
Microsoft Windows NT Workstation 4.0 SP5
-
Microsoft Windows NT Workstation 4.0 SP4
-
Microsoft Windows NT Workstation 4.0 SP3
-
Microsoft Windows NT Workstation 4.0 SP2
-
Microsoft Windows NT Workstation 4.0 SP1
-
Microsoft Windows NT Workstation 4.0
-
Microsoft Windows XP Home
-
Microsoft Windows XP Professional
Microsoft Office Web Components 2002
+
Microsoft BizTalk Server 2002 Developer Edition
+
Microsoft BizTalk Server 2002 Enterprise Edition
+
Microsoft Commerce Server 2002
+
Microsoft Money 2002
+
Microsoft Money 2003
+
Microsoft Office XP
+
Microsoft Project 2002
+
Microsoft Project Server 2002
Microsoft Office Web Components 2000 0
+
Microsoft Back Office Server 2000
+
Microsoft Back Office Server 2000
+
Microsoft BizTalk Server 2000 Developer Edition SP2
+
Microsoft BizTalk Server 2000 Developer Edition SP2
+
Microsoft BizTalk Server 2000 Developer Edition SP1a
+
Microsoft BizTalk Server 2000 Developer Edition SP1a
+
Microsoft BizTalk Server 2000 Developer Edition
+
Microsoft BizTalk Server 2000 Developer Edition
+
Microsoft BizTalk Server 2000 Enterprise Edition SP2
+
Microsoft BizTalk Server 2000 Enterprise Edition SP2
+
Microsoft BizTalk Server 2000 Enterprise Edition SP1a
+
Microsoft BizTalk Server 2000 Enterprise Edition SP1a
+
Microsoft BizTalk Server 2000 Enterprise Edition
+
Microsoft BizTalk Server 2000 Enterprise Edition
+
Microsoft BizTalk Server 2000 Standard Edition SP2
+
Microsoft BizTalk Server 2000 Standard Edition SP2
+
Microsoft BizTalk Server 2000 Standard Edition SP1a
+
Microsoft BizTalk Server 2000 Standard Edition SP1a
+
Microsoft BizTalk Server 2000 Standard Edition
+
Microsoft BizTalk Server 2000 Standard Edition
+
Microsoft BizTalk Server 2002 Developer Edition
+
Microsoft BizTalk Server 2002 Enterprise Edition
+
Microsoft Commerce Server 2000 SP2
+
Microsoft Commerce Server 2000 SP2
+
Microsoft Commerce Server 2000 SP1
+
Microsoft Commerce Server 2000 SP1
+
Microsoft Commerce Server 2000
+
Microsoft Commerce Server 2000
+
Microsoft Commerce Server 2002
+
Microsoft Internet Explorer for Unix SP2
+
Microsoft ISA Server 2000 SP2
+
Microsoft ISA Server 2000 SP1
+
Microsoft ISA Server 2000 SP1
+
Microsoft ISA Server 2000 FP1
+
Microsoft ISA Server 2000
+
Microsoft ISA Server 2000
+
Microsoft ISA Server 2000 Enterprise Edition SP2
+
Microsoft ISA Server 2000 Enterprise Edition SP1
+
Microsoft ISA Server 2000 Enterprise Edition
+
Microsoft Office 2000 SP2
+
Microsoft Office 2000 SP2
+
Microsoft Office 2000 SP1
+
Microsoft Office 2000 SP1
+
Microsoft Office 2000
+
Microsoft Office 2000
+
Microsoft Office XP SP3
+
Microsoft Office XP SP2
+
Microsoft Office XP SP1
+
Microsoft Office XP
+
Microsoft Small Business Server 2000 0
+
Microsoft Visual Studio .NET 2002
+
Microsoft Visual Studio .NET 2003 Enterprise Architect
+
Microsoft Visual Studio .NET Enterprise Architect Edition
+
Microsoft Visual Studio .NET Enterprise Developer Edition
Microsoft Internet Explorer 6.0
-
Microsoft Windows 2000 Advanced Server SP2
-
Microsoft Windows 2000 Advanced Server SP2
-
Microsoft Windows 2000 Advanced Server SP2
-
Microsoft Windows 2000 Advanced Server SP1
-
Microsoft Windows 2000 Advanced Server SP1
-
Microsoft Windows 2000 Advanced Server SP1
-
Microsoft Windows 2000 Advanced Server
-
Microsoft Windows 2000 Advanced Server
-
Microsoft Windows 2000 Advanced Server
-
Microsoft Windows 2000 Datacenter Server SP2
-
Microsoft Windows 2000 Datacenter Server SP2
-
Microsoft Windows 2000 Datacenter Server SP2
-
Microsoft Windows 2000 Datacenter Server SP1
-
Microsoft Windows 2000 Datacenter Server SP1
-
Microsoft Windows 2000 Datacenter Server SP1
-
Microsoft Windows 2000 Datacenter Server
-
Microsoft Windows 2000 Datacenter Server
-
Microsoft Windows 2000 Datacenter Server
-
Microsoft Windows 2000 Professional SP2
-
Microsoft Windows 2000 Professional SP2
-
Microsoft Windows 2000 Professional SP2
-
Microsoft Windows 2000 Professional SP1
-
Microsoft Windows 2000 Professional SP1
-
Microsoft Windows 2000 Professional SP1
-
Microsoft Windows 2000 Professional
-
Microsoft Windows 2000 Professional
-
Microsoft Windows 2000 Professional
-
Microsoft Windows 2000 Server SP2
-
Microsoft Windows 2000 Server SP2
-
Microsoft Windows 2000 Server SP2
-
Microsoft Windows 2000 Server SP1
-
Microsoft Windows 2000 Server SP1
-
Microsoft Windows 2000 Server SP1
-
Microsoft Windows 2000 Server
-
Microsoft Windows 2000 Server
-
Microsoft Windows 2000 Server
-
Microsoft Windows 2000 Terminal Services SP2
-
Microsoft Windows 2000 Terminal Services SP2
-
Microsoft Windows 2000 Terminal Services SP2
-
Microsoft Windows 2000 Terminal Services SP1
-
Microsoft Windows 2000 Terminal Services SP1
-
Microsoft Windows 2000 Terminal Services SP1
-
Microsoft Windows 2000 Terminal Services
-
Microsoft Windows 2000 Terminal Services
-
Microsoft Windows 2000 Terminal Services
-
Microsoft Windows 98
-
Microsoft Windows 98
-
Microsoft Windows 98
-
Microsoft Windows 98SE
-
Microsoft Windows 98SE
-
Microsoft Windows 98SE
-
Microsoft Windows ME
-
Microsoft Windows ME
-
Microsoft Windows ME
-
Microsoft Windows NT 4.0 SP6a
-
Microsoft Windows NT 4.0 SP6a
-
Microsoft Windows NT Enterprise Server 4.0 SP6a
-
Microsoft Windows NT Enterprise Server 4.0 SP6a
-
Microsoft Windows NT Enterprise Server 4.0 SP6a
-
Microsoft Windows NT Server 4.0 SP6a
-
Microsoft Windows NT Server 4.0 SP6a
-
Microsoft Windows NT Server 4.0 SP6a
-
Microsoft Windows NT Terminal Server 4.0 SP6a
-
Microsoft Windows NT Terminal Server 4.0 SP6a
-
Microsoft Windows NT Workstation 4.0 SP6a
-
Microsoft Windows NT Workstation 4.0 SP6a
-
Microsoft Windows NT Workstation 4.0 SP6a
+
Microsoft Windows Server 2003 Datacenter Edition
+
Microsoft Windows Server 2003 Datacenter Edition
+
Microsoft Windows Server 2003 Datacenter Edition
+
Microsoft Windows Server 2003 Datacenter Edition Itanium 0
+
Microsoft Windows Server 2003 Datacenter Edition Itanium 0
+
Microsoft Windows Server 2003 Enterprise Edition
+
Microsoft Windows Server 2003 Enterprise Edition
+
Microsoft Windows Server 2003 Enterprise Edition
+
Microsoft Windows Server 2003 Enterprise Edition Itanium 0
+
Microsoft Windows Server 2003 Enterprise Edition Itanium 0
+
Microsoft Windows Server 2003 Enterprise Edition Itanium 0
+
Microsoft Windows Server 2003 Standard Edition
+
Microsoft Windows Server 2003 Standard Edition
+
Microsoft Windows Server 2003 Standard Edition
+
Microsoft Windows Server 2003 Web Edition
+
Microsoft Windows Server 2003 Web Edition
+
Microsoft Windows Server 2003 Web Edition
+
Microsoft Windows XP Home
+
Microsoft Windows XP Home
+
Microsoft Windows XP Home
+
Microsoft Windows XP Professional
+
Microsoft Windows XP Professional
+
Microsoft Windows XP Professional
Not Vulnerable:
Discussion
Microsoft Office XP/Internet Explorer OWC File Creation Vulnerability
A reliable source has announced a vulnerability affecting users of Microsoft Internet Explorer and Microsoft Office XP.
The vulnerability is related to Office Web Components (OWC), a set of plugins for MSIE that have been taken off of Microsoft's website for security reasons.
It is possible to abuse OWC in combination with a malicious .xls or .xla file to cause an almost arbitrary file to be written to a client system. This issue affects systems that still have OWC installed and may be exploited from a malicious webpage.
This issue is a variation of the problem described in Bugtraq ID 4398.
Solution / Fix
Microsoft Office XP/Internet Explorer OWC File Creation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Office XP/Internet Explorer OWC File Creation Vulnerability