|
|
|
Credit:
The information has been provided by Symantec.
The original article can be found at: http://www.symantec.com/enterprise/research/SYMSA-2006-007.txt
|
|
Vulnerable Systems:
* Microsoft Office 2003 Service Pack 1 or Service Pack 2
* Microsoft Access 2003
* Microsoft Excel 2003
* Microsoft Excel 2003 Viewer
* Microsoft FrontPage 2003
* Microsoft InfoPath 2003
* Microsoft OneNote 2003
* Microsoft Outlook 2003
* Microsoft PowerPoint 2003
* Microsoft Project 2003
* Microsoft Publisher 2003
* Microsoft Visio 2003
* Microsoft Word 2003
* Microsoft Word 2003 Viewer
* Microsoft Office XP Service Pack 3
* Microsoft Access 2002
* Microsoft Excel 2002
* Microsoft FrontPage 2002
* Microsoft Outlook 2002
* Microsoft PowerPoint 2002
* Microsoft Publisher 2002
* Microsoft Visio 2002
* Microsoft Word 2002
* Microsoft Office 2000 Service Pack 3
* Microsoft Access 2000
* Microsoft Excel 2000
* Microsoft FrontPage 2000
* Microsoft Outlook 2000
* Microsoft PowerPoint 2000
* Microsoft Publisher 2000
* Microsoft Word 2000
* Microsoft Project 2002 Service Pack 1
* Microsoft Visio 2002 Service Pack 2
* Microsoft Project 2000 Service Release 1
* Microsoft Office 2004 for Mac
* Microsoft Office v. X for Mac
Immune Systems:
* Microsoft Works Suites:
* Microsoft Works Suite 2004
* Microsoft Works Suite 2005
* Microsoft Works Suite 2006
The problem resides in the code of MSO.DLL, a shared library used by Office applications, so the vulnerability can be exploited using different attack vectors.
For example, the vulnerability can be exploited using a malformed Excel 2003 file. By changing the size of the Unicode "Sheet Name" string with an incorrect size, it is possible to generate an integer overflow condition. Excel 2003 will crash while opening the malformed file due to an access violation error with an invalid value of :
EAX=0xFFFFFFFC.
MOV EDX,DWORD PTR DS:[EAX-4]
ADD EAX,-4
ADD EDX,4
CVE Information:
CVE-2006-1540
|
|
|
|