Home→Descriptions→SA15998
| Secunia ID | |
| CVE-ID | |
| Release Date |
12 Jul 2005 |
| Last Change |
13 Jul 2005 |
| Criticality | |
| Solution Status |
Vendor Patch |
| Software |
Microsoft Office 2000 |
| Where | |
| Impact |
System accessThis covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user. |
| Description |
Lord Yup has reported a vulnerability in Microsoft Word, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to a boundary error within the parsing of fonts. This can be exploited to cause a stack-based buffer overflow by tricking a user into opening a specially crafted Word document. Successful exploitation allows execution of arbitrary code. |
| Solution |
Apply patches. Microsoft Office 2000 SP3: Microsoft Office XP SP3: Microsoft Works Suite 2000: Microsoft Works Suite 2001: Microsoft Works Suite 2002: Microsoft Works Suite 2003: Microsoft Works Suite 2004: |
| Reported by |
Lord Yup |
| Original Advisory |
MS05-035 (903672): iDEFENSE: |