Vulnerable Systems:
Lotus Notes version 8.5 and prior
The vulnerability occurs during the processing of tag information contained within an Applix document. A memory copy operation within a loop may cause tag data to overflow the bounds of a stack buffer. This condition may lead to arbitrary code execution.
Exploitation of this vulnerability results in the execution of arbitrary code in the context of the user opening an attachment delivered via email. In order to be successful, an attacker must social engineer the victim into processing a specially crafted email attachment in a certain way. Specifically, the victim must open the attachment and click the view button on the attachment dialog box.
Workaround:
A workaround is available to disable Applix Documents within the Lotus Notes file viewer:
Open the keyview.ini file in the Lotus Notes program data directory (C:\Program Files\IBM\Lotus\Notes\Data) and comment out all references to assr.dll. To comment out a reference, proceed the line with a semi-colon ';'.