Microsoft_Office_Word_File_Processing_Buffer_Overflow_attack

Strike ID:
G09-3fn01
CVSS:
9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)
False Positive:
f
Variants:
1
Year:
2009

Description

A buffer overflow vulnerability exists in Microsoft Office Word while processing Word files. This vulnerability is due to a boundary error when processing specially crafted records. Remote attackers can exploit this vulnerability by enticing target users to open a malicious Word file, potentially causing arbitrary code to be injected and executed in the security context of the current user. In an attack scenario, where arbitrary code is injected and executed on the target machine, the behaviour of the target is dependent on the intention of the malicious code. If such an attack is not executed successfully, the vulnerable application may terminate unexpectedly. If unexpected termination of the vulnerable application is the sole result of an attack, there is no impact to the overall operation of the target host. It is, however, possible to lose all unsaved data due to the abnormal termination.

CVE

References

Bid