CERT-In Vulnerability Note
CIVN-2008-0193
Microsoft Windows WordPad Text Converter File Handling Memory Corruption Vulnerability
Original Issue Date:December 18, 2008
Severity Rating: HIGH
Systems Affected
- Windows Server 2003 x64 Edition SP2 and prior
- Windows Server 2003 SP2 and prior
- Windows XP Professional x64 Edition SP2 and prior
- Windows XP SP2 and prior
- Windows 2000 SP4 and prior
Overview
Microsoft Windows contains vulnerability in the WordPad Text Converter that could allow an unauthenticated, remote attacker to corrupt memory and execute arbitrary code on the system.
Description
WordPad Text Converters are a default component of Microsoft Windows operating systems which allow users who do not have Microsoft Office Word installed to open documents in Microsoft Windows Write .wri and Microsoft Office Word 6.0, Microsoft Office Word 97, Microsoft Office Word 2000, and Microsoft Office Word 2002 .doc file formats. These text converters also allow users to save documents in the Word 6.0 file format.
The vulnerability is due to improper validation of Word 97 files in the WordPad Text Converter in WordPad. An unauthenticated, remote attacker could exploit this vulnerability by convincing a user to view a malicious . doc , . wri , or . rtf document. The processing of the document in WordPad could trigger memory corruption.
Workaround
- Disable the WordPad Text Converter for Word 97 file format
For detailed steps and impact of applying these workarounds refer to Microsoft security 960906 - Block .wri files at the Internet perimeter.
- Do not open or save unsolicited files that received from untrusted sources or that received unexpectedly from trusted sources.
Vendor Information
Microsoft
http://www.microsoft.com/technet/security/advisory/960906.mspx
References
Microsoft
http://www.microsoft.com/technet/security/advisory/960906.mspx
US-CERT
http://www.kb.cert.org/vuls/id/926676
SecurityTracker
http://securitytracker.com/alerts/2008/Dec/1021376.html
Cisco Security Center
http://tools.cisco.com/security/center/viewAlert.x?alertId=17238
CVE Name
CVE-2008-4841
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|