Description: Some vulnerabilities have been reported in Microsoft Word, which can be exploited by malicious people to compromise a user's system.
1) An unspecified error within the handling of data in arrays can be exploited via a specially crafted Word document.
2) An unspecified error when handling objects in Word Document streams can be exploited to cause memory corruption via a specially crafted Word document.
NOTE: This vulnerability is currently being actively exploited.
3) An unspecified error when processing certain rich text (RTF) properties can be exploited to cause memory corruption via a specially crafted file.
Successful exploitation of the vulnerabilities allows execution of arbitrary code.
Provided and/or discovered by: 1) Reported by the vendor.
2) Discovered as a 0-day.
3) Discovered by an anonymous person and reported via iDefense Labs.
Changelog: 2007-05-08: Added additional information from Microsoft. Updated "Solution" section.
2007-05-09: Added additional information from iDefense Labs. Added links to US-CERT.
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.