PT-2016-1049 · Microsoft · Visual Basic 6.0 Runtime+27
Publicado
2016-01-12
·
Atualizado
2018-10-12
·
CVE-2016-0012
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Office 2007 SP3
Excel 2007 SP3
PowerPoint 2007 SP3
Visio 2007 SP3
Word 2007 SP3
Office 2010 SP2
Excel 2010 SP2
PowerPoint 2010 SP2
Visio 2010 SP2
Word 2010 SP2
Office 2013 SP1
Excel 2013 SP1
PowerPoint 2013 SP1
Visio 2013 SP1
Word 2013 SP1
Excel 2013 RT SP1
PowerPoint 2013 RT SP1
Word 2013 RT SP1
Office 2016
Excel 2016
PowerPoint 2016
Visio 2016
Word 2016
Visual Basic 6.0 Runtime
Description
A security feature bypass exists when Microsoft Office fails to use the Address Space Layout Randomization (ASLR) security feature, allowing an attacker to more reliably predict the memory offsets of specific instructions in a given call stack. An attacker who successfully exploited it could bypass the Address Space Layout Randomization (ASLR) security feature, which helps protect users from a broad class of vulnerabilities. The security feature bypass by itself does not allow arbitrary code execution. However, an attacker could use this ASLR bypass in conjunction with another vulnerability, such as a remote code execution vulnerability, to more reliably run arbitrary code on a target system.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Excel 2007
Excel 2010
Excel 2013
Excel 2013 Rt
Excel 2016
Office 2007
Office
Office 2010
Office 2013
Office 2016
Office Excel
Office Powerpoint
Office Visio
Office Word
Powerpoint 2007
Powerpoint 2010
Powerpoint 2013 Rt
Powerpoint 2016
Visio 2007
Visio 2010
Visio 2013
Visio 2016
Visual Basic 6.0 Runtime
Word 2007
Word 2010
Word 2013
Word 2013 Rt
Word 2016