|
Microsoft Office is prone to an integer overflow condition. The MSO.DLL library fails to properly sanitize user-supplied input when parsing the number of colours in bitmap images, resulting in a heap-based buffer overflow. With a specially crafted bitmap image embedded in an Office file, a context-dependent attacker can potentially execute arbitrary code on a user's system.
|