|
|
|
|
| |
Credit:
The information has been provided by Nicolas Joly.
The original article can be found at: http://osdir.com/ml/bugtraq.security/2010-10/msg00111.html
|
| |
Vulnerable Systems:
* Microsoft Office 2010
* Microsoft Office 2007 Service Pack 2
* Microsoft Office 2003 Service Pack 3
* Microsoft Office 2002 Service Pack 3
* Microsoft Office 2008 for Mac
* Microsoft Office 2004 for Mac
* Microsoft Office Web Apps
* Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Service Pack 2
* Open XML File Format Converter for Mac
* Microsoft Word Viewer
The vulnerability is caused by a stack overflow error when processing certain structures in a Word document, which could be exploited by remote attackers to execute arbitrary code by tricking a user into opening a specially crafted Word file.
Patch Availability:
Apply MS10-079 security update:
http://www.microsoft.com/technet/security/bulletin/ms10-079.mspx
CVE Information:
CVE-2010-3214
Disclosure Timeline:
2010-04-08 - Vendor notified
2010-04-08 - Vendor response
2010-10-12 - Coordinated public Disclosure
|
|
|
|
|