PT-2011-4438 · Microsoft · Office Publisher
Will Dormann
·
Published
2011-12-13
·
Updated
2018-10-12
·
CVE-2011-3411
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Publisher version 2003 SP3
Description
A remote code execution issue exists due to the incorrect handling of values in memory when parsing Publisher files. This could allow an attacker to execute arbitrary code by creating a specially crafted Publisher file. The attacker could convince the user to open this file, potentially via an email attachment or a compromised website. If the user has administrative rights, the attacker could gain complete control of the system, allowing them to install programs, view, change, or delete data, or create new accounts with full user rights. Users with fewer user rights may be less affected.
Recommendations
For Microsoft Publisher 2003 SP3, consider avoiding the use of potentially malicious Publisher files until a fix is available. As a temporary workaround, restrict the use of Microsoft Publisher for opening files from untrusted sources.
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Office Publisher