CERT-In Vulnerability Note
CIVN-2006-0136
Microsoft Word malformed data structure vulnerability
Original Issue Date:December 28, 2006
Updated: February 14, 2007
Severity Rating: HIGH
Systems Affected
Microsoft Word 2000 Microsoft Word 2003 Microsoft Word X for the Mac Microsoft Word XP Microsoft Word Viewer 2003
Overview
A remote code execution vulnerability has been reported in Microsoft Word that could be exploited by an attackers to take complete control of the vulnerable system.
Description
The vulnerability is caused due to a memory corruption error while handling malformed data structure in a Word document.
The attacker could exploit this vulnerability by creating a specially crafted Word file. An attacker could host a web site containing the specially crafted word file and could persuade the user to visit the website typically by getting them click on a link to the website. Opening this Crafted word file could corrupt the system memory and allow attacker to execute arbitrary code.
Workaround
Do not open or save Word files that received from un-trusted sources or received unexpectedly from trusted sources .
Solution
Apply appropriate patches as mentioned in Microsoft Security Bulletin MS07-014
References
FrSIRT
http://www.frsirt.com/english/advisories/2006/4920
USCERT
http://www.kb.cert.org/vuls/id/166700
CVE Name
CVE-2006-6456
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|