Microsoft Office Word RTF, Word, and HTML Processing Errors Let Remote Users Execute Arbitrary Code
|
|
SecurityTracker Alert ID: 1024298 |
|
SecurityTracker URL: http://securitytracker.com/id/1024298
|
|
CVE Reference:
CVE-2010-1900, CVE-2010-1901, CVE-2010-1902, CVE-2010-1903
(Links to External Site)
|
Updated: Sep 2 2010
|
Original Entry Date: Aug 10 2010
|
Impact:
Execution of arbitrary code via network, User access via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 2002 SP3, 2003 SP3, 2007 SP2, 2004 for Mac, 2008 for Mac; and prior service packs
|
Description:
Several vulnerabilities were reported in Microsoft Office Word. A remote user can cause arbitrary code to be executed on the target user's system.
A remote user can create a Word file with specially crafted records that, when loaded by the target user, will execute arbitrary code on the target system [CVE-2010-1900]. The code will run with the privileges of the target user.
L.W.Z of team509 reported this vulnerability via TippingPoint's Zero Day Initiative.
A remote user can create a specially crafted RTF file or e-mail message that, when loaded by the target user via Word, will execute arbitrary code on the target system [CVE-2010-1901]. The code will run with the privileges of the target user.
Wushi of team509 reported this vulnerability via VeriSign iDefense Labs.
A remote user can create a specially crafted RTF file or e-mail message that, when loaded by the target user via Word, will trigger a buffer overflow and execute arbitrary code on the target system [CVE-2010-1902]. The code will run with the privileges of the target user.
team509 reported this vulnerability via VeriSign iDefense Labs.
A remote user can create a Word file that contains specially crafted HTML linked objects that, when loaded by the target user, will trigger a memory corruption error and execute arbitrary code [CVE-2010-1903]. The code will run with the privileges of the target user.
Rodrigo Rubira Branco of the Check Point IPS Research Team reported this vulnerability.
|
Impact:
A remote user can create a file that, when loaded by the target user, will execute arbitrary code on the target user's system.
|
Solution:
The vendor has issued the following fixes:
Microsoft Office XP Service Pack 3, Microsoft Office Word 2002 Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?familyid=978eb887-25b6-4dde-a2ec-d2d1e7f1a434
Microsoft Office 2003 Service Pack 3, Microsoft Office Word 2003 Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?familyid=4360bcec-0731-4d4a-89eb-7d28a4607f06
2007 Microsoft Office System Service Pack 2, Microsoft Office Word 2007 Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=0d7210a3-662e-41e7-affc-ae94f9d89388
On September 1, 2010, the vendor noted that Word 7 users need to apply security update package KB2277947 in addition to security update package KB2251419.
Microsoft Office 2004 for Mac:
http://www.microsoft.com/downloads/details.aspx?familyid=d2f44d4a-7cd8-4514-b3ff-1770bc47d595
Microsoft Office 2008 for Mac:
http://www.microsoft.com/downloads/details.aspx?familyid=6ece112f-0ca7-4b1f-ad20-603950edee66
Open XML File Format Converter for Mac:
http://www.microsoft.com/downloads/details.aspx?familyid=a7b834a3-5a44-42d4-afe9-6ef207333834
Microsoft Office Word Viewer:
http://www.microsoft.com/downloads/details.aspx?familyid=39fe2229-9201-4270-bdc1-20bc8e30a766
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=ed5b9671-651d-41f3-aed3-93ee8a28657f
Microsoft Works 9:
http://www.microsoft.com/downloads/details.aspx?familyid=feb121ad-e5f6-40e2-bf12-045ae5c2a754
A restart may be required.
The Microsoft advisory is available at:
http://www.microsoft.com/technet/security/bulletin/ms10-056.mspx
|
Vendor URL: www.microsoft.com/technet/security/bulletin/ms10-056.mspx (Links to External Site)
|
Cause:
Access control error, Boundary error
|
Underlying OS:
UNIX (OS X), Windows (Any)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Tue, 10 Aug 2010 17:54:45 +0000
Subject: http://www.microsoft.com/technet/security/bulletin/ms10-056.mspx
|
Microsoft Security Bulletin MS10-056 - Critical: Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution (2269638)
CVE-2010-1900
CVE-2010-1901
CVE-2010-1902
CVE-2010-1903
|
|