CERT-In Vulnerability Note
CIVN-2004-0067
Microsoft Word 6.0 document Converter Buffer Overflow Vulnerabilities
Original Issue Date:December 15, 2004
Severity Rating: MEDIUM
Systems Affected
- Microsoft Windows 2000 Advanced Server
- Microsoft Windows 2000 Datacenter Server
- Microsoft Windows 2000 Professional
- Microsoft Windows 2000 Server
- Microsoft Windows 98
- Microsoft Windows 98 Second Edition
- Microsoft Windows Millennium Edition ME
- Microsoft Windows NT 4.0 Server
- Microsoft Windows NT 4.0 Server, Terminal Server Edition
- Microsoft Windows Server 2003 Datacenter Edition
- Microsoft Windows Server 2003 Enterprise Edition
- Microsoft Windows Server 2003 Standard Edition
- Microsoft Windows Server 2003 Web Edition
- Microsoft Windows XP Home Edition
- Microsoft Windows XP Professional
Overview
Two vulnerabilities exist in Microsoft Word 6.0 Converter. These vulnerabilities can be exploited by a remote attacker to take complete control of the affected system with privileges of target user.
Impact
Successful exploitation of the vulnerability allows execution of arbitrary code with privileges of the target user.
Description
Two vulnerabilities Table conversion and Font conversion have been reported in Microsoft Word 6.0 document converter due to unchecked buffer. The Windows 6.0 Converter MSWRD632.WPC helps users convert documents from Word format to the Rich Text Format. The RTF is usually used by WordPad.
To exploit this vulnerability an attacker could send a malicious file or host a website and convince the user to open the malicious document having .wri, .rtf, or .doc file extension. If the user opens the malicious document manually via double click or after being prompted by Internet Explorer, the WordPad fails to open the file and allows the attacker to execute arbitrary code and take complete control of the affected system with privileges of target user. Successful exploitation of these vulnerabilities requires user interaction and handler for Word for Windows 6.0 converter enabled.
Workaround
- Do not open Windows 6.0 documents from untrusted sources using Microsoft WordPad
- Use Microsoft Word to open the Word for Windows 6.0 document
- Disable the handler for Word for Windows 6.0 converter
Solution
Apply appropriate patches as mentioned in Microsoft Security Bulletin
MS04-041
Vendor Information
Microsoft Security Bulletin MS04-041
http://www.microsoft.com/technet/security/bulletin/ms04-041.mspx
References
Secunia advisory
http://secunia.com/advisories/13462/
iDEFENSE Security Advisory
http://www.idefense.com/application/poi/display?id=162
Securitytracker advisory
http://securitytracker.com/alerts/2004/Dec/1012514.html
CVE Name
CAN-2004-0571
CAN-2004-0901
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|