Microsoft Office ASLR Remote Security Bypass Weakness
BID:67273
Info
Microsoft Office ASLR Remote Security Bypass Weakness
| Bugtraq ID: | 67273 |
| Class: | Design Error |
| CVE: |
CVE-2014-1809 |
| Remote: | Yes |
| Local: | No |
| Published: | May 13 2014 12:00AM |
| Updated: | May 13 2014 12:00AM |
| Credit: | Microsoft |
| Vulnerable: |
Microsoft Office 2010 (64-bit edition) SP1 Microsoft Office 2010 (32-bit edition) SP1 Microsoft Office 2007 SP3 |
| Not Vulnerable: | |
Discussion
Microsoft Office ASLR Remote Security Bypass Weakness
Microsoft Office is prone to a remote security-bypass weakness that may cause a library to use a predictable base address.
This weakness may allow attackers to predict the base address of a library in certain circumstances and in turn bypass the Address Space Layout Randomization (ASLR) protection mechanisms of applications. This may aid in further attacks and lead to arbitrary code execution.
Microsoft Office is prone to a remote security-bypass weakness that may cause a library to use a predictable base address.
This weakness may allow attackers to predict the base address of a library in certain circumstances and in turn bypass the Address Space Layout Randomization (ASLR) protection mechanisms of applications. This may aid in further attacks and lead to arbitrary code execution.
Exploit / POC
Microsoft Office ASLR Remote Security Bypass Weakness
Currently, we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Office ASLR Remote Security Bypass Weakness
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.