PT-2010-2968 · Microsoft · Wordpad+16
Published
2010-06-08
·
Updated
2018-10-12
·
CVE-2010-1263
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Windows Shell and WordPad in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7
Microsoft Office XP SP3
Office 2003 SP3
Office System 2007 SP1 and SP2
Description
A remote code execution issue exists due to improper validation of COM objects during instantiation in affected Microsoft software. This allows attackers to execute arbitrary code via a crafted file. An attacker who successfully exploits this issue could take complete control of an affected system, then install programs, view, change, or delete data, or create new accounts with full user rights. Users with fewer user rights on the system could be less affected than those operating with administrative user rights.
Recommendations
For Windows Shell and WordPad in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, update to a newer version that includes the fix for this issue.
For Microsoft Office XP SP3, update to a newer version that includes the fix for this issue.
For Office 2003 SP3, update to a newer version that includes the fix for this issue.
For Office System 2007 SP1 and SP2, update to a newer version that includes the fix for this issue.
As a temporary workaround, consider restricting the use of WordPad and the opening of shortcut files from network or WebDAV shares until a patch is available.
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Office Xp
Office
Office 2003
Office Excel
Office Powerpoint
Office Publisher
Office System 2007
Office Visio
Office Word
Windows
Windows 7
Windows Server 2003
Windows Server 2008
Windows Shell
Windows Vista
Windows Xp
Wordpad