Eng
  1. Skip to navigation
  2. Skip to content
  3. Skip to sidebar


Vulnerability protection

Microsoft Office vulnerability could allow remote code execution


Report ID: MS201208006
Date Published: 15 August 2012

Criticality: Important
Compromise Type: remote-code-execution
Compromise From: remote


Affected Product/Component:

Microsoft Office 2007
Microsoft Office 2010




Summary

A vulnerability in Microsoft Office could allow a remote attacker to execute code and take control of a compromised system.



Detailed Description

Microsoft has released a security update to address a vulnerability in Microsoft Office. It was caused by improper handling of specially crafted CGM files, which leads to memory corruption. An attacker could then take advantage of the condition to execute arbitrary code on the affected system, and gains similar right as the current logged-on user.

This issue has been resolved through the latest update, which disables the loading of CGM graphic files in Microsoft Office applications. Users are recommended to install the update as a protection measure againsts potential exploit attempts.



CVE Reference

CVE-2012-2524



Solution

Install the latest security patch for applicable system, available for download from (https://technet.microsoft.com/en-us/security/bulletin/ms12-057)




Security Advisories

For a list of known vulnerabilities affecting F-Secure products and the released fixes, please refer to the Security Advisories page.