1. Skip to navigation
  2. Skip to content
  3. Skip to secondary-content




Microsoft Office Word File Information Memory Corruption Vulnerability

Report ID: SA200906012
Source: F-Secure
Date of Discovery: 10.11.2009
Criticality: Urgent
Affects:
Microsoft Office Word 2002 Service Pack 3
Microsoft Office Word 2003 Service Pack 3
Microsoft Office 2004 for Mac
Microsoft Office 2008 for Mac
Open XML File Format Converter for Mac
Microsoft Office Word Viewer 2003 Service Pack 3
Microsoft Office Word Viewer

Compromise From: From remote
Compromise Type: Remote code execution

Summary

A vulnerability has been reported in Microsoft Office Word 2002, Word 2003, Office 2004 for Mac, Office 2008 for Mac Open XML File Format Converter for Mac and Office Word Viewer. If exploited, the vulnerability could allow an attacker to take complete control of the affected system.

Detailed Description

The vulnerability can be exploited by a specially crafted Word document. If successful, the attacker can perform such actions as viewing or modifying data, installing programs and creating new  accounts.