[NT] Microsoft Word Document Code Execution
- From: SecuriTeam <support@xxxxxxxxxxxxxx>
- Date: 7 Dec 2006 17:34:48 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
The SecuriTeam alerts list - Free, Accurate, Independent.
Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html
- - - - - - - - -
Microsoft Word Document Code Execution
------------------------------------------------------------------------
SUMMARY
There is a vulnerability in Microsoft Word which according to reports can
result in code execution.
DETAILS
There is a vulnerability in Microsoft Word which according to reports can
be used for code execution
Not much is known of this 0day, but we decided to issue an advisory as an
heads-up warning. You can find more on it here:
<http://blogs.securiteam.com/index.php/archives/755>
http://blogs.securiteam.com/index.php/archives/755
Workaround:
There is no workaround available at this time. We suggest caution when
opening untrusted Word documents.
ADDITIONAL INFORMATION
The original article can be found at:
<http://www.microsoft.com/technet/security/advisory/929433.mspx>
http://www.microsoft.com/technet/security/advisory/929433.mspx
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@xxxxxxxxxxxxxx
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@xxxxxxxxxxxxxx
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Prev by Date: [UNIX] F-Prot Antivirus Heap Overflow and DoS
- Next by Date: [NT] Cumulative Security Update for Internet Explorer (MS06-072)
- Previous by thread: [UNIX] F-Prot Antivirus Heap Overflow and DoS
- Next by thread: [NT] Cumulative Security Update for Internet Explorer (MS06-072)
- Index(es):
Relevant Pages
- [NT] Microsoft Word 6.0/95 Document Converter Buffer Overflow (MS04-041)
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... WordPad is "a word processing
application that uses the MFC rich edit ... Remote exploitation of a buffer overflow vulnerability
in Microsoft ... Microsoft Word format files into the Rich Text Format natively handled
by ... (Securiteam) - [NT] Microsoft Word RTF File Parsing Heap Corruption Vulnerability
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Microsoft Word RTF File Parsing
Heap Corruption Vulnerability ... Microsoft Word is "a word processing application
from Microsoft Office. ... Rich Text Format (RTF) is a document file format developed by
Microsoft ... (Securiteam) - [NT] Microsoft WORD Hlink Local Buffer Overflow (Exploit)
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Microsoft WORD Hlink Local
Buffer Overflow ... The information in this bulletin is provided "AS IS" without warranty
of any kind. ... In no event shall we be liable for any damages whatsoever including direct,
indirect, incidental, consequential, loss of business profits or special damages. ... (Securiteam) - [NT] Microsoft Office XP Remote Buffer Overflow Technical Details (MS05-005)
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... When a ".doc" file is opened inside
Internet Explorer, Microsoft Word XP ... "takes over" and opens that doc file. ...
http://example.com/myfile.doc is a valid request. ... (Securiteam) - [NT] Microsoft Word Font Parsing Buffer Overflow Vulnerability (Technical Details, MS-05-035)
... The following security advisory is sent to the securiteam mailing list, and
can be found at the SecuriTeam web site: http://www.securiteam.com ... Microsoft Word is
the word processing component of the ... * 24.03.05 - Initial vendor response ...
(Securiteam)