Get a Pentest and security assessment of your IT network.

Advisories

iDEFENSE Security Advisory 2007-05-08.3

iDefense Security Advisory 05.08.07 – Remote exploitation of a heap corruption vulnerability in Microsoft Corp.’s Word could allow attackers to execute arbitrary code under the privileges of the target user. This vulnerability specifically exists in the handling of property strings of certain control words in an RTF document. In certain circumstances, these property strings can be written into a memory region which has already been deallocated and heap corruption can occur. iDefense has confirmed that winword.exe file version 11.0.8106.0, as included with a fully patched Microsoft Word 2003 SP2, is vulnerable. Previous versions of Microsoft Word are also likely to be affected.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/56634/05.08.07-3.txt

Source: https://packetstormsecurity.com/files/56634/iDEFENSE-Security-Advisory-2007-05-08.3.html

Related posts
Advisories

Secunia Security Advisory 15646

Advisories

Secunia Security Advisory 18761

Advisories

deluxeBBflaws.txt

Advisories

Mandriva Linux Security Advisory 2007.061