Microsoft Office and Excel Memory Corruption Bugs Let Remote Users Execute Arbitrary Code
|
SecurityTracker Alert ID: 1019578 |
SecurityTracker URL: http://securitytracker.com/id/1019578
|
CVE Reference:
CVE-2008-0113, CVE-2008-0118
(Links to External Site)
|
Date: Mar 11 2008
|
Impact:
Execution of arbitrary code via network, User access via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 2000 SP3, 2003 SP2, and 2004 for Mac; Excel Viewer 2003 and Excel Viewer 2003 SP3
|
Description:
Two vulnerabilities were reported in Microsoft Office. A remote user can cause arbitrary code to be executed on the target user's system.
A remote user can create a specially crafted Excel or Office file that, when loaded by the target user, will trigger a memory corruption error and execute arbitrary code on the target system. The code will run with the privileges of the target user.
A specially crafted Excel file can trigger arbitrary code execution [CVE-2008-0113].
A specially crafted Office file can trigger arbitrary code execution [CVE-2008-0118].
An anonymous researcher reported one of the vulnerabilities. Arnaud Dovi reported the other vulnerability via Zero Day Initiative.
|
Impact:
A remote user can create a file that, when loaded by the target user, will execute arbitrary code on the target user's system.
|
Solution:
The vendor has issued the following fixes.
Microsoft Office 2000 Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?familyid=72735aa1-e22c-40ed-8c79-38fba89979aa
Microsoft Office XP Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?familyid=9cf8aafa-71a5-4017-b53c-4e80ef6e1188
Microsoft Office 2003 Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=9f25922c-d3c2-4ef1-b164-8a21a77d29aa
Microsoft Office Excel Viewer 2003:
http://www.microsoft.com/downloads/details.aspx?familyid=9f25922c-d3c2-4ef1-b164-8a21a77d29aa
Microsoft Office Excel Viewer 2003 Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?familyid=9f25922c-d3c2-4ef1-b164-8a21a77d29aa
Microsoft Office 2004 for Mac:
http://www.microsoft.com/downloads/details.aspx?FamilyId=95DCEB37-B35F-46DB-B280-DB0F3B298AA9
A restart is not required.
The Microsoft advisory is available at:
http://www.microsoft.com/technet/security/bulletin/ms08-016.mspx
|
Vendor URL: www.microsoft.com/technet/security/bulletin/ms08-016.mspx (Links to External Site)
|
Cause:
Access control error
|
Underlying OS: UNIX (macOS/OS X), Windows (Any)
|
|
Message History:
None.
|
Source Message Contents
|
|
[Original Message Not Available for Viewing]
|
|