Secunia Advisory SA30143Microsoft Word Two Code Execution Vulnerabilities
|
||||
Description
Two vulnerabilities have been reported in Microsoft Word, which can be exploited by malicious people to compromise a user's system. 1) An error when parsing objects in rich text format (.rtf) files can be exploited to cause a heap-based buffer overflow e.g. when a user opens a specially crafted .rtf file containing malformed strings with Word or previews a specially crafted e-mail containing malformed strings as rich text or HTML. 2) An error exists in the processing of cascading style sheets (CSS) values and can be exploited to corrupt memory when a specially crafted HTML file is opened using Word. Successful exploitation may allow execution of arbitrary code. Solution Provided and/or discovered by Other references Deep Links Do you have additional information related to this advisory?Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this information to vuln@secunia.com
|
||||