PT-2016-1049 · Microsoft · Visual Basic 6.0 Runtime+27

Publicado

2016-01-12

·

Atualizado

2018-10-12

·

CVE-2016-0012

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Office 2007 SP3 Excel 2007 SP3 PowerPoint 2007 SP3 Visio 2007 SP3 Word 2007 SP3 Office 2010 SP2 Excel 2010 SP2 PowerPoint 2010 SP2 Visio 2010 SP2 Word 2010 SP2 Office 2013 SP1 Excel 2013 SP1 PowerPoint 2013 SP1 Visio 2013 SP1 Word 2013 SP1 Excel 2013 RT SP1 PowerPoint 2013 RT SP1 Word 2013 RT SP1 Office 2016 Excel 2016 PowerPoint 2016 Visio 2016 Word 2016 Visual Basic 6.0 Runtime
Description A security feature bypass exists when Microsoft Office fails to use the Address Space Layout Randomization (ASLR) security feature, allowing an attacker to more reliably predict the memory offsets of specific instructions in a given call stack. An attacker who successfully exploited it could bypass the Address Space Layout Randomization (ASLR) security feature, which helps protect users from a broad class of vulnerabilities. The security feature bypass by itself does not allow arbitrary code execution. However, an attacker could use this ASLR bypass in conjunction with another vulnerability, such as a remote code execution vulnerability, to more reliably run arbitrary code on a target system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-00116
CVE-2016-0012

Produtos afetados

Excel 2007
Excel 2010
Excel 2013
Excel 2013 Rt
Excel 2016
Office 2007
Office
Office 2010
Office 2013
Office 2016
Office Excel
Office Powerpoint
Office Visio
Office Word
Powerpoint 2007
Powerpoint 2010
Powerpoint 2013 Rt
Powerpoint 2016
Visio 2007
Visio 2010
Visio 2013
Visio 2016
Visual Basic 6.0 Runtime
Word 2007
Word 2010
Word 2013
Word 2013 Rt
Word 2016