Skip to main content

Microsoft Office Remote Code Execution Vulnerability

Last Update Date: 18 Nov 2014 Release Date: 12 Nov 2014 3040 Views

RISK: Medium Risk

TYPE: Clients - Productivity Products

TYPE: Productivity Products
  1. Microsoft Office Double Delete Remote Code Execution Vulnerability
    A remote code execution vulnerability exists in the context of the current user that is caused when Microsoft Word does not properly handle objects in memory while parsing specially crafted Office files. Microsoft received information about the vulnerability through coordinated vulnerability disclosure. When this security bulletin was issued, Microsoft had not received any information to indicate that this vulnerability had been publicly used to attack customers. The security update addresses the vulnerability by correcting how Microsoft Office parses specially crafted files.
  2. Microsoft Office Bad Index Remote Code Execution Vulnerability
    A remote code execution vulnerability exists in the context of the current user that is caused when Microsoft Word improperly handles objects in memory while parsing specially crafted Office files. This could corrupt system memory in such a way as to allow an attacker to execute arbitrary code. Microsoft received information about these vulnerability through coordinated vulnerability disclosure. When this security bulletin was issued, Microsoft had not received any information to indicate that this vulnerability had been publicly used to attack customers. The security update addresses the vulnerability by correcting how Microsoft Office parses specially crafted files.
  3. Microsoft Office Invalid Pointer Remote Code Execution Vulnerability
    A remote code execution vulnerability exists in the context of the local user that is caused when Microsoft Word does not properly handle objects in memory while parsing specially crafted Office files. This could corrupt system memory in such a way as to allow an attacker to execute arbitrary code. Microsoft received information about these vulnerability through coordinated vulnerability disclosure. When this security bulletin was issued, Microsoft had not received any information to indicate that this vulnerability had been publicly used to attack customers. The security update addresses the vulnerability by correcting how Microsoft Office parses specially crafted files.

Impact

  • Remote Code Execution

System / Technologies affected

  • Microsoft Office 2007 Service Pack 3
  • Microsoft Word Viewer
  • Microsoft Office Compatibility Pack Service Pack 3

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link