Vulnerable Systems:
* Microsoft Office XP SP3
* Microsoft Office 2003 SP3
* Microsoft Office Converter Pack
The vulnerability is caused by an integer truncation error in the PICT import filter (PICTIM32.FLT). This can be exploited to cause a heap-based buffer overflow by e.g. tricking a user into importing a specially crafted PICT file.
Disclosure Timeline:
14/07/2009 - Vendor notified.
14/07/2009 - Vendor response.
08/11/2010 - Vendor informed that December is the final deadline.
20/12/2010 - Public disclosure.