CERT-In Vulnerability Note
CIVN-2012-0115
Remote Code Execution Vulnerability in Microsoft Word
Original Issue Date:December 12, 2012
Severity Rating: HIGH
Systems Affected
- Microsoft Office 2003 Service Pack 3
- Microsoft Office 2007 Service Pack 2/Pack 3
- Microsoft Office 2010 Service Pack 1 (32-bit editions)/ (64-bit editions)
- Microsoft Word Viewer
- Microsoft Office Compatibility Pack Service Pack 2/ Pack 3
- Microsoft SharePoint Server 2010 Service Pack 1
- Microsoft Office Web Apps 2010 Service Pack 1
Component Affected
- Microsoft Word 2003 Service Pack 3
- Microsoft Word 2007 Service Pack 2 /Pack 3
- Microsoft Word 2010 Service Pack 1 (32-bit editions)/ (64-bit editions)
- Word Automation Services
Overview
A vulnerability has been reported in Microsoft Word which could be exploited by a remote attacker to execute arbitrary code to take control of the affected system affected in the context of currently logged-in user.
Description
This vulnerability exists in Microsoft Word while parsing rich text format data . The vulnerability could be exploited by a remote attacker by sending specially crafted RTF-formatted data in the contents of an email message.
A successful exploitation of the vulnerability could allow the remote attacker to execute arbitrary code on the system with the privileges of the logged in user.
Workaround
- Read emails in plain text.
- Use Microsoft Office File Block policy to block the opening of RTF documents from unknown or untrusted sources and locations.
Solution
Apply appropriate patches as mentioned in Microsoft Security Bulletin
MS12-079
Vendor Information
Microsoft
http://technet.microsoft.com/en-us/security/bulletin/ms12-079
References
SecurityTracker
http://www.securitytracker.com/id/1027859
CISCO
http://tools.cisco.com/security/center/viewAlert.x?alertId=27537
CVE Name
CVE-2012-2539
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|