OSVDB ID: 31888

Title: Microsoft Malware Protection Engine PDF File Parsing Remote Code Execution

Info

Disclosure

Feb 13, 2007

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Feb 13, 2007

Description

A local overflow exists in Malware Protection Engine. mpengine.dll fails to validate PDF files resulting in an integer overflow. With a specially crafted file, an attacker can cause arbitrary code execution resulting in a loss of integrity.

Classification

Location: Local Access Required, Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Patch / RCS
Exploit: Exploit Unknown
Disclosure: OSVDB Verified, Vendor Verified

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, Microsoft has released a patch to address this vulnerability.

Products

Microsoft Corporation

Live OneCare

Unspecified

Antigen for Exchange

9.x

Antigen for SMTP Gateway

9.x

Windows Defender

Unspecified

Windows Defender x64

Unspecified

Windows Defender in Windows Vista

Unspecified

Forefront Security for Exchange Server

Unspecified

Forefront Security for Sharepoint

Unspecified

References

Credit

  • Neel Mehta -   -
  • Alex Wheeler - advisorieshustlelabs.com - Hustle Labs


Direct URL: http://osvdb.org/31888