MicrosoftOffice Web Components Remote Code Execution Vulnerability
RISK: Medium Risk
A vulnerability has been identified in Microsoft Office Web Components, which could be exploited by remote attackers to compromise an affected system. This issue is caused by a memory corruption error in the "OWC10.DLL" and "OWC11.DLL" ActiveX controls, which could be exploited by remote attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.
Note: This vulnerability is currently being exploited in the wild.
Impact
- Remote Code Execution
System / Technologies affected
- Microsoft Office XP Service Pack 3
- Microsoft Office 2003 Service Pack 3
- Microsoft Office XP Web Components Service Pack 3
- Microsoft Office 2003 Web Components Service Pack 3
- Microsoft ISA Server 2004 Standard Edition Service Pack 3
- Microsoft ISA Server 2004 Enterprise Edition Service Pack 3
- Microsoft ISA Server 2006
- Microsoft ISA Server 2006 Supportability Update
- Microsoft ISA Server 2006 Service Pack 1
- Microsoft Office Small Business Accounting 2006
Solutions
There is no patch available for this vulnerability currently.
Please refer to the workaround provided by the vendor.
http://support.microsoft.com/kb/973472/#FixItForMe
Vulnerability Identifier
Source
Related Link
- http://secunia.com/advisories/35800/
- http://www.vupen.com/english/advisories/2009/1867
- http://www.microsoft.com/technet/security/advisory/973472.mspx
- http://blogs.technet.com/msrc/archive/2009/07/13/microsoft-security-advisory-973472-released.aspx
- http://blogs.technet.com/srd/archive/2009/07/13/more-information-about-the-office-web-components-activex-vulnerability.aspx
Share with