SecurityTracker.com
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 


Category:   OS (Microsoft)  >   Windows DLL (Any) Vendors:   Microsoft
Microsoft OLE Automation Memory Corruption Bug Lets Remote Users Execute Arbitrary Code
SecurityTracker Alert ID:  1018560
SecurityTracker URL:  http://securitytracker.com/id/1018560
CVE Reference:   CVE-2007-2224   (Links to External Site)
Updated:  Aug 15 2007
Original Entry Date:  Aug 14 2007
Impact:   Execution of arbitrary code via network, User access via network
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): 2000 SP4, 2003 SP2, XP SP2
Description:   A vulnerability was reported in Microsoft OLE Automation. A remote user can cause arbitrary code to be executed on the target user's system. Visual Basic is affected. Office for Mac is affected.

A remote user can create specially crafted HTML that, when loaded by the target user, will trigger a memory corruption error in the object linking and embedding (OLE) automation protocol implementation and execute arbitrary code on the target system. The code will run with the privileges of the target user.

Office 2004 for Mac is affected.

Visual Basic 6 is affected.

The vendor was notified on May 17, 2006.

Zero Day Initiative and iDefense separately reported this vulnerability.

Impact:   A remote user can create HTML that, when loaded by the target user, will execute arbitrary code on the target user's system.
Solution:   The vendor has issued the following fixes:

Windows 2000 Service Pack 4:

http://www.microsoft.com/downloads/details.aspx?FamilyId=5c35b6e8-732a-4451-b5d4-23ed63e6e792

Windows XP Service Pack 2:

http://www.microsoft.com/downloads/details.aspx?FamilyId=6e8de050-8589-4831-ae19-075c93509485

Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2:

http://www.microsoft.com/downloads/details.aspx?FamilyId=b85bb583-dc61-4d37-b458-208f5bb07ece

Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2:

http://www.microsoft.com/downloads/details.aspx?FamilyId=15d4d4fa-9bab-4da5-978e-f89c78c8086a

Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2:

http://www.microsoft.com/downloads/details.aspx?FamilyId=6608d722-3ef8-4085-b771-7b17bb0ba06e

Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium-based Systems:

http://www.microsoft.com/downloads/details.aspx?FamilyId=fc04451a-0696-4a21-b2b6-f02d4e2c33bf

Microsoft Visual Basic 6.0 Service Pack 6 (KB924053):

http://www.microsoft.com/downloads/details.aspx?FamilyId=E1646FB0-29D5-4A6E-A8D2-304C4D7735B7

Office 2004 for Mac:

http://www.microsoft.com/mac/downloads.aspx#Office2004

A restart is required.

The Microsoft advisory is available at:

http://www.microsoft.com/technet/security/bulletin/ms07-043.mspx

Vendor URL:  www.microsoft.com/technet/security/bulletin/ms07-043.mspx (Links to External Site)
Cause:   Access control error

Message History:   None.


 Source Message Contents



[Original Message Not Available for Viewing]


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

This web site uses cookies for web analytics. Learn More

Copyright 2022, SecurityGlobal.net LLC