OSVDB ID: 34387

Title: Microsoft Word Data Array Handling Remote Code Execution

Info

Disclosure

May 08, 2007

Discovery

Unknown

Dates

Exploit

Unknown

Solution

May 08, 2007

Description

Microsoft Office contains a flaw that may allow a malicious user to execute arbitrary code on the system. The issue is due to the Word failing to properly verify data within certain arrays. The issue is triggered by a specially crafted Word file that may allow arbitrary code execution resulting in a loss of integrity.

Classification

Location: Local Access Required, Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Patch / RCS
Exploit: Exploit Unknown
Disclosure: OSVDB Verified, Vendor Verified

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, Microsoft has released patches for all versions to address this vulnerability.

Products

Microsoft Corporation

Works Suite

2004
2005
2006

Office

2000 SP3
XP SP3
2003 SP2
2004 for Mac

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/34387