1. Skip to navigation
  2. Skip to content
  3. Skip to secondary-content




Vulnerabilities in Microsoft Office Could Allow Remote Code Execution

Report ID: SA201006549
Source: F-Secure
Date of Discovery: 10.11.2010
Criticality: Critical
Affects:
Microsoft Office XP
Microsoft Office 2003
Microsoft Office 2007
Microsoft Office 2010
Microsoft Office 2004 for Mac
Microsoft Office 2008 for Mac
Microsoft Office for Mac 2011
Open XML File Format Converter for Mac

Compromise From: From remote
Compromise Type: Remote code execution

Summary

Five vulnerabilities identified in Microsoft Office products could lead to an attacker executing arbitrary code and gaining user rights on the affected system.

Detailed Description

Microsoft has issued a security update to resolve multiple vulnerabilities affecting Microsoft Office products for both Windows and Mac platforms. Five vulnerabilities were identified, each one of them could lead to remote code execution.

 

RTF Stack Buffer Overflow Vulnerability

This remote code execution vulnerability was caused by system memory corruption that results when Microsoft Office software parses specially crafted RTF-formatted data. An attacker could exploit this vulnerability to execute arbitrary code and obtain user rights on the affected system. The update addresses this issue by modifying the way RTF-formatted data are parsed. 

 

Office Art Drawing Records Vulnerability, Drawing Exception Handling Vulnerability, and MSO Large SPID Read AV Vulnerability

This remote code execution vulnerabilities were caused by system memory corruption that results when a user opens a specially crafted Office file. An attacker could exploit these vulnerabilities to execute arbitrary code and obtain user rights on affected system. The update addresses this issues by modifying the way Microsoft Office software parses files. 

 

Insecure Library Loading Vulnerability

This remote code execution vulnerability results when a specially crafted DDL file is loaded into memory. For this vulnerability to exist, the user has to open a document contained within the same working directory as the DDL file. An attacker who successfully exploit this vulnerability, could execute arbitrary code and obtain user rights on the affected system. The update addresses this issue by ensuring that a more appropriate and secure search order are used when loading libraries. 

 

Solution

Install the latest update for applicable product.

 

Microsoft Office Suites

 

Microsoft Office for Mac

** The security updates for Microsoft Office 2004 for Mac, Microsoft Office 2008 for Mac and Open XML File Format Converter for Mac are unavailable at this time.

Original Reference

CVE Reference

CVE-2010-3333
CVE-2010-3334
CVE-2010-3335
CVE-2010-3336
CVE-2010-3337