Title: Microsoft Word RTF Rich Text Properties Parsing Remote Code Execution
Info
Disclosure
May 08, 2007
Discovery
Feb 27, 2007
Dates
Exploit
Unknown
Solution
Unknown
Description
Microsoft Word 2003 SP2 (winword.exe file version 11.0.8106.0) contains a flaw that may allow remote code execution. The issue is due to a heap corruption vulnerability in Word, specifically in the handling of property strings in RTF documents. Exploitation requires a target user to load a specially crafted RTF document. When loaded, arbitrary code may be executed with the same permissions as the target user.
Classification
Location:
Local Access Required,
Remote / Network Access
Attack Type:
Other
Impact:
Loss of Integrity
Exploit:
Exploit Private,
Exploit Unknown
Solution
Microsoft has released a patch to address this issue. Additionally, it is possible to correct the flaw by implementing the following workaround(s):
Change the default association for RTF files to use WordPad, which is not affected by this vulnerability.