PT-2011-4438 · Microsoft · Office Publisher

Will Dormann

·

Published

2011-12-13

·

Updated

2018-10-12

·

CVE-2011-3411

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Publisher version 2003 SP3
Description A remote code execution issue exists due to the incorrect handling of values in memory when parsing Publisher files. This could allow an attacker to execute arbitrary code by creating a specially crafted Publisher file. The attacker could convince the user to open this file, potentially via an email attachment or a compromised website. If the user has administrative rights, the attacker could gain complete control of the system, allowing them to install programs, view, change, or delete data, or create new accounts with full user rights. Users with fewer user rights may be less affected.
Recommendations For Microsoft Publisher 2003 SP3, consider avoiding the use of potentially malicious Publisher files until a fix is available. As a temporary workaround, restrict the use of Microsoft Publisher for opening files from untrusted sources.

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-3411

Affected Products

Office Publisher