Microsoft Office Graphics Filters Let Remote Users Execute Arbitrary Code
|
SecurityTracker Alert ID: 1024887 |
SecurityTracker URL: http://securitytracker.com/id/1024887
|
CVE Reference:
CVE-2010-3945, CVE-2010-3946, CVE-2010-3947, CVE-2010-3949, CVE-2010-3950, CVE-2010-3951, CVE-2010-3952
(Links to External Site)
|
Date: Dec 14 2010
|
Impact:
Execution of arbitrary code via network, User access via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): XP SP3, 2003 SP3, 2007 SP2, 2010
|
Description:
Several vulnerabilities were reported in Microsoft Office. A remote user can cause arbitrary code to be executed on the target user's system.
A remote user can create a specially crafted CGM, TIFF, PICT, or FlashPix image file that, when loaded by the target user, will execute arbitrary code on the target system. The code will run with the privileges of the target user.
Microsoft Office Converter Pack and Microsoft Works 9 are also affected.
Yamata Li of Palo Alto Networks, Alin Rad Pop of Secunia Research, and Dyon Balding of Secunia Research reported this vulnerability.
|
Impact:
A remote user can create a file that, when loaded by the target user, will execute arbitrary code on the target user's system.
|
Solution:
The vendor has issued the following fixes:
Microsoft Office XP Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?familyid=724d0ad6-ba5f-4dbf-b280-3fb36335d33b
Microsoft Office 2003 Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?familyid=976857e9-77fc-4667-88ca-7637e57536cd
Microsoft Office 2007 Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=676eeed6-f2b7-4265-afc7-a82ffdbeb290
Microsoft Office 2010 (32-bit editions):
http://www.microsoft.com/downloads/details.aspx?familyid=6d644494-b530-4b37-bc37-8a8a7edefe53
Microsoft Office 2010 (64-bit editions):
http://www.microsoft.com/downloads/details.aspx?familyid=58e54779-aa8f-41b3-9993-8cec12c49082
Microsoft Office Converter Pack:
http://www.microsoft.com/downloads/details.aspx?familyid=dcded2ee-0673-4afe-abe6-04941a2ad306
Microsoft Works 9:
http://www.microsoft.com/downloads/details.aspx?familyid=10f6f330-05d8-4b60-9ebb-822a7321ac0f
A restart may be required.
The Microsoft advisory is available at:
http://www.microsoft.com/technet/security/bulletin/ms10-105.mspx
|
Vendor URL: www.microsoft.com/technet/security/bulletin/ms10-105.mspx (Links to External Site)
|
Cause:
Access control error, Boundary error
|
Underlying OS: Windows (Any)
|
|
Message History:
None.
|
Source Message Contents
|
|
[Original Message Not Available for Viewing]
|
|