Skip to main content

Microsoft Office Denial of Service Vulnerability

Last Update Date: 8 Apr 2014 12:34 Release Date: 8 Apr 2014 4054 Views

RISK: High Risk

TYPE: Clients - Productivity Products

TYPE: Productivity Products

A vulnerability was identified in Microsoft Office. A remote user can cause denial of service conditions.

 

A remote user can send a specially crafted XML document that, when processed by the target application, will trigger an entity expansion flaw to consume excessive memory resources and cause the application to hang.

 

This can be exploited by sending email to the target user to cause the target user's Outlook to freeze when opening the email.

 

An XML Document Type Definition (DTD) containing several nested entities can trigger this flaw.

 

* NOTE : No patch is available.


Impact

  • Denial of Service

System / Technologies affected

  • Microsoft Office 2007-2013

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Currently no patch is available.

Vulnerability Identifier


Source


Related Link