Microsoft Office and Excel Memory Corruption Bugs Let Remote Users Execute Arbitrary Code
|
|
SecurityTracker Alert ID: 1019578
|
|
SecurityTracker URL: http://securitytracker.com/id?1019578
|
|
CVE Reference: CVE-2008-0113
, CVE-2008-0118
(Links to External Site)
|
Date: Mar 11 2008
|
Impact: Execution of arbitrary code via network, User access via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Advisory: Microsoft Security Bulletin
|
Version(s): 2000 SP3, 2003 SP2, and 2004 for Mac; Excel Viewer 2003 and Excel Viewer 2003 SP3
|
Description: Two vulnerabilities were reported in Microsoft Office. A remote user can cause arbitrary code to be executed on the target user's system.
A remote user can create a specially crafted Excel or Office file that, when loaded by the target user, will trigger a memory corruption
error and execute arbitrary code on the target system. The code will run with the privileges of the target user.
A specially
crafted Excel file can trigger arbitrary code execution [CVE-2008-0113].
A specially crafted Office file can trigger arbitrary
code execution [CVE-2008-0118].
An anonymous researcher reported one of the vulnerabilities. Arnaud Dovi reported the other
vulnerability via Zero Day Initiative.
|
Impact: A remote user can create a file that, when loaded by the target user, will execute arbitrary code on the target user's system.
|
Solution: The vendor has issued the following fixes.
Microsoft Office 2000 Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?familyid=72735aa1-e22c-40ed-8c79-38f
ba89979aa
Microsoft Office XP Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?familyid=9cf8aafa-71a5-4017-b53c-4e80ef6e1188
Microsoft
Office 2003 Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=9f25922c-d3c2-4ef1-b164-8a21a77d29aa
Microsoft
Office Excel Viewer 2003:
http://www.microsoft.com/downloads/details.aspx?familyid=9f25922c-d3c2-4ef1-b164-8a21a77d29aa
Microsoft
Office Excel Viewer 2003 Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?familyid=9f25922c-d3c2-4ef1-b164-8a21a77d29aa
Microsoft
Office 2004 for Mac:
http://www.microsoft.com/downloads/details.aspx?FamilyId=95DCEB37-B35F-46DB-B280-DB0F3B298AA9
A restart
is not required.
The Microsoft advisory is available at:
http://www.microsoft.com/technet/security/bulletin/ms08-016.mspx
|
Vendor URL: www.microsoft.com/technet/security/bulletin/ms08-016.mspx (Links to External Site)
|
Cause: Access control error
|
Underlying OS: UNIX (OS X), Windows (Any)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Tue, 11 Mar 2008 12:22:17 -0500
Subject: Microsoft Security Bulletin MS08-016 Critical: Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (949030)
|
http://www.microsoft.com/technet/security/bulletin/ms08-016.mspx
CVE-2008-0113
CVE-2008-0118
|
|