English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Microsoft Word for Windows Converter Buffer Overflow Vulnerabilities


Secunia ID

SA13462

CVE-ID

CVE-2004-0571, CVE-2004-0901

Release Date

14 Dec 2004

Last Change

15 Dec 2004

Criticality

Moderately Critical

Solution Status

Vendor Patch

Where

From remote

Impact
System access

This covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user.

Description

Some vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system.

The vulnerabilities are caused due to boundary errors in the table and font conversion in the Word for Windows 6.0 converter. This can be exploited to cause a buffer overflow by e.g. tricking a user into opening a malicious ".wri", ".rtf", or ".doc" document in WordPad.

Successful exploitation allows execution of arbitrary code.

NOTE: Exploitation requires that the handler for Word for Windows 6.0 converter is enabled.

Solution

Apply patches.

Microsoft Windows NT Server 4.0 (requires Service Pack 6a):
http://www.microsoft.com/downloads/details.aspx?FamilyId=AC2DE442-6C98-4545-8072-2BE4064466CD

Microsoft Windows NT Server 4.0 Terminal Server Edition (requires Service Pack 6):
http://www.microsoft.com/downloads/details.aspx?FamilyId=A49CC5E2-1072-4BF6-A7F3-029957EBB1C2

Microsoft Windows 2000 (requires Service Pack 3 or Service Pack 4):
http://www.microsoft.com/downloads/details.aspx?FamilyId=C4B9D079-13F0-4E1E-834B-D2077838B9E1

Microsoft Windows XP (requires Service Pack 1 or Service Pack 2):
http://www.microsoft.com/downloads/details.aspx?FamilyId=703DE7D8-68D9-4A92-8C59-87221F89EF14

Microsoft Windows XP 64-Bit Edition (requires Service Pack 1):
http://www.microsoft.com/downloads/details.aspx?FamilyId=A7A5077B-4BF0-441A-AB43-D6A5E1B698E9

Microsoft Windows XP 64-Bit Edition Version 2003:
http://www.microsoft.com/downloads/details.aspx?FamilyId=005930C0-4C3F-4FD3-9E08-D586632C5486

Microsoft Windows Server 2003:
http://www.microsoft.com/downloads/details.aspx?FamilyId=D1747015-10C8-411F-8C26-773B59008FD8

Microsoft Windows Server 2003 64-Bit Edition:
http://www.microsoft.com/downloads/details.aspx?FamilyId=005930C0-4C3F-4FD3-9E08-D586632C5486

For other versions of Microsoft Windows, disable the Word for Windows converter.

Reported by

Greg Jones of KPMG UK and Lord Yup.

Original Advisory

MS04-041 (KB885836):
http://www.microsoft.com/technet/security/bulletin/ms04-041.mspx

iDEFENSE:
http://www.idefense.com/application/poi/display?id=162&type=vulnerabilities