English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Microsoft Word Document Parsing Buffer Overflow Vulnerabilities


Secunia ID

SA12758

CVE-ID

CVE-2004-0963, CVE-2005-0558

Release Date

07 Oct 2004

Last Change

10 Aug 2005

Criticality

Highly Critical

Solution Status

Vendor Patch

Software

Microsoft Office 2000
Microsoft Office 2003 Professional Edition
Microsoft Office 2003 Small Business Edition
Microsoft Office 2003 Standard Edition
Microsoft Office 2003 Student and Teacher Edition
Microsoft Office Word Viewer 2003
Microsoft Office XP
Microsoft Word 2000
Microsoft Word 2002
Microsoft Word 2003
Microsoft Works Suite 2001
Microsoft Works Suite 2002
Microsoft Works Suite 2003
Microsoft Works Suite 2004

Where

From remote

Impact
System access

This covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user.

Description

Two vulnerabilities have been reported in Microsoft Word, which can be exploited by malicious people to compromise a user's system.

The vulnerabilities are caused due to boundary errors within the parsing of document files. This can be exploited to cause buffer overflows by tricking a user into opening a specially crafted Word document.

Successful exploitation allows execution of arbitrary code with the privileges of the user running Microsoft Word.

Solution

Apply patches.

Microsoft Word 2000 and Microsoft Works Suite 2001:
http://www.microsoft.com/downloads/details.aspx?FamilyId=9F4B6868-2F94-478F-B0BC-0DA3E0571523

Microsoft Word 2002, Microsoft Works Suite 2002, Microsoft Works Suite 2003, and Microsoft Works Suite 2004:
http://www.microsoft.com/downloads/details.aspx?FamilyId=34998255-E004-4A29-9418-35C5818E54CB

Microsoft Office Word 2003:
http://www.microsoft.com/downloads/details.aspx?FamilyId=9158279D-4421-4932-9318-02CA829A9B43

Microsoft Word 2003 Viewer:
http://www.microsoft.com/downloads/details.aspx?familyid=95E24C87-8732-48D5-8689-AB826E7B8FDF&displaylang=en

Reported by

First vulnerability discovered by:
HexView

Second vulnerability discovered by:
Alex Li

Original Advisory

MS05-023 (KB890169):
http://www.microsoft.com/technet/security/Bulletin/MS05-023.mspx

Hexview:
http://www.hexview.com/docs/20041006-1.txt