Microsoft Office Multiple Remote Code Execution Vulnerabilities (MS06-012)

CVE ID : CVE-2005-4131 - CVE-2006-0009 - CVE-2006-0028 - CVE-2006-0029 - CVE-2006-0030 - CVE-2006-0031
Rated as : Critical 
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2006-03-15

Technical Description

Multiple vulnerabilities have been identified in Microsoft Office, which could be exploited by remote attackers to execute arbitrary commands.

The first issue is due to a memory corruption error in Excel when handling a malformed range, which could be exploited by attackers to compromise a vulnerable system via a malicious document.

The second flaw is due to a memory corruption error in Office when handling a specially crafted "routing slip", which could be exploited by attackers to compromise a vulnerable system via a malicious document.

The third vulnerability is due to a memory corruption error in Excel when handling malformed BOOLERR records in a BIFF file, which could be exploited by attackers to compromise a vulnerable system via a malicious document.

The fourth flaw is due to a memory corruption error in Excel when handling a specially crafted description, which could be exploited by attackers to compromise a vulnerable system via a malicious document.

The fifth issue is due to a memory corruption error in Excel when handling specially crafted graphics, which could be exploited by attackers to compromise a vulnerable system via a malicious document.

The sixth vulnerability is due to a memory corruption error in Excel when handling malformed records, which could be exploited by attackers to compromise a vulnerable system via a malicious Excel document.

Affected Products

Microsoft Office 2000 Service Pack 3
Microsoft Word 2000
Microsoft Excel 2000
Microsoft Outlook 2000
Microsoft PowerPoint 2000
Microsoft Office 2000 MultiLanguage Packs
Microsoft Office XP Service Pack 3
Microsoft Word 2002
Microsoft Excel 2002
Microsoft Outlook 2002
Microsoft PowerPoint 2002
Microsoft Office XP Multilingual User Interface Packs
Microsoft Office 2003 Service Pack 1
Microsoft Office 2003 Service Pack 2
Microsoft Excel 2003
Microsoft Excel 2003 Viewer
Microsoft Works Suite 2000
Microsoft Works Suite 2001
Microsoft Works Suite 2002
Microsoft Works Suite 2003
Microsoft Works Suite 2004
Microsoft Works Suite 2005
Microsoft Works Suite 2006
Microsoft Office X for Mac
Microsoft Excel X for Mac
Microsoft Office 2004 for Mac
Microsoft Excel 2004 for Mac

Solution

Apply patches :
http://www.microsoft.com/technet/security/Bulletin/MS06-012.mspx

References

http://www.frsirt.com/english/advisories/2006/0950
http://www.microsoft.com/technet/security/Bulletin/MS06-012.mspx

Credits

Vulnerabilities reported by Peter Winter-Smith, Ollie Whitehouse, Arnaud Dovi, Dejun Meng, Eyas and the vendor.

ChangeLog

2006-03-15 : Initial release

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值