CERT-In Vulnerability Note
CIVN-2009-0138
Microsoft Office Word Remote Code Execution Vulnerability
Original Issue Date:November 11, 2009
Severity Rating: HIGH
Systems Affected
- Microsoft Office Word 2002 SP 3
- Microsoft Office Word 2003 SP 3
- Microsoft Office 2004 for Mac
- Microsoft Office 2008 for Mac
- Open XML File Format Converter for Mac
- Microsoft Office Word Viewer 2003 SP 3
- Microsoft Office Word Viewer
Overview
A vulnerability has been identified in Microsoft Office Word, which could be exploited by attackers to compromise a vulnerable system.
Description
The vulnerability exists because Microsoft Word does not properly handle malformed documents.
An unauthenticated, remote attacker could exploit this vulnerability by convincing a user to open a malicious document. If the user opens the file, the attacker could execute arbitrary code with the privileges of the user.
Workaround
Do not open Word documents received from untrusted sources Use the Microsoft Office Isolated Conversion Environment MOICE when opening files from unknown or untrusted sources
For detailed steps of these workaround refer to Microsoft Security Bulletin MS09-068
Solution
Apply appropriate patches as mentioned in Microsoft Security Bulletin
MS09-068
Vendor Information
Microsoft
http://www.microsoft.com/technet/security/bulletin/MS09-068.mspx
References
Microsoft
http://www.microsoft.com/technet/security/bulletin/ms09-068.mspx
Vupen Security
http://www.vupen.com/english/advisories/2009/3194
SecurityFocus
http://www.securityfocus.com/bid/36950/
Security Lab
http://en.securitylab.ru/notification/387575.php
CVE Name
CVE-2009-3135
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|