PT-2010-4652 · Microsoft · Word Web App+6

Nicolas Joly

·

Publicado

2010-10-13

·

Atualizado

2018-10-12

·

CVE-2010-3214

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Word versions 2002 SP3, 2003 SP3, 2007 SP2, and 2010 Office 2004 and 2008 for Mac Open XML File Format Converter for Mac Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 Word Viewer Office Web Apps Word Web App
Description A stack-based buffer overflow issue allows remote attackers to execute arbitrary code via a crafted Word document. This issue exists in the way Microsoft Word handles stack validation when parsing a specially crafted Word file. An attacker who successfully exploits this issue could take complete control of an affected system, enabling them to install programs, view, change, or delete data, or create new accounts with full user rights. Users with fewer user rights on the system could be less impacted than users operating with administrative user rights.
Recommendations For Microsoft Word 2002 SP3, update to a newer version to mitigate the risk. For Microsoft Word 2003 SP3, update to a newer version to mitigate the risk. For Microsoft Word 2007 SP2, update to a newer version to mitigate the risk. For Microsoft Word 2010, update to a newer version to mitigate the risk. For Office 2004 and 2008 for Mac, update to a newer version to mitigate the risk. For Open XML File Format Converter for Mac, update to a newer version to mitigate the risk. For Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2, update to a newer version to mitigate the risk. For Word Viewer, update to a newer version to mitigate the risk. For Office Web Apps, update to a newer version to mitigate the risk. For Word Web App, update to a newer version to mitigate the risk.

Correção

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-3214

Produtos afetados

Office Word
Office
Office Compatibility Pack
Office Web Apps
Open Xml File Format Converter For Mac
Word Viewer
Word Web App