PT-2010-4652 · Microsoft · Word Web App+6
Nicolas Joly
·
Publicado
2010-10-13
·
Atualizado
2018-10-12
·
CVE-2010-3214
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Word versions 2002 SP3, 2003 SP3, 2007 SP2, and 2010
Office 2004 and 2008 for Mac
Open XML File Format Converter for Mac
Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2
Word Viewer
Office Web Apps
Word Web App
Description
A stack-based buffer overflow issue allows remote attackers to execute arbitrary code via a crafted Word document. This issue exists in the way Microsoft Word handles stack validation when parsing a specially crafted Word file. An attacker who successfully exploits this issue could take complete control of an affected system, enabling them to install programs, view, change, or delete data, or create new accounts with full user rights. Users with fewer user rights on the system could be less impacted than users operating with administrative user rights.
Recommendations
For Microsoft Word 2002 SP3, update to a newer version to mitigate the risk.
For Microsoft Word 2003 SP3, update to a newer version to mitigate the risk.
For Microsoft Word 2007 SP2, update to a newer version to mitigate the risk.
For Microsoft Word 2010, update to a newer version to mitigate the risk.
For Office 2004 and 2008 for Mac, update to a newer version to mitigate the risk.
For Open XML File Format Converter for Mac, update to a newer version to mitigate the risk.
For Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2, update to a newer version to mitigate the risk.
For Word Viewer, update to a newer version to mitigate the risk.
For Office Web Apps, update to a newer version to mitigate the risk.
For Word Web App, update to a newer version to mitigate the risk.
Correção
RCE
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Office Word
Office
Office Compatibility Pack
Office Web Apps
Open Xml File Format Converter For Mac
Word Viewer
Word Web App