Vulnerable Systems:
* Autonomy KeyView version 10.4
* Autonomy KeyView version 10.9
The vulnerability is caused by a boundary error in the Spreadsheet Lotus 123 reader (wkssr.dll) when converting floating point values in certain record types. This can be exploited to cause a stack-based buffer overflow via a specially crafted file. Successful exploitation allows execution of arbitrary code.
Patch Availability:
Apply patches available from the vendor.