OSVDB ID: 34388

Title: Microsoft Word RTF Rich Text Properties Parsing Remote Code Execution

Info

Disclosure

May 08, 2007

Discovery

Feb 27, 2007

Dates

Exploit

Unknown

Solution

Unknown

Description

Microsoft Word 2003 SP2 (winword.exe file version 11.0.8106.0) contains a flaw that may allow remote code execution. The issue is due to a heap corruption vulnerability in Word, specifically in the handling of property strings in RTF documents. Exploitation requires a target user to load a specially crafted RTF document. When loaded, arbitrary code may be executed with the same permissions as the target user.

Classification

Location: Local Access Required, Remote / Network Access
Attack Type: Other
Impact: Loss of Integrity
Exploit: Exploit Private, Exploit Unknown

Solution

Microsoft has released a patch to address this issue. Additionally, it is possible to correct the flaw by implementing the following workaround(s): Change the default association for RTF files to use WordPad, which is not affected by this vulnerability.

Products

Microsoft Corporation

Word

2003 SP2

References

Credit

  • iDefense - iDefense


Direct URL: http://osvdb.org/34388