English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Microsoft Word Three Code Execution Vulnerabilities


Secunia ID

SA24122

CVE-ID

CVE-2007-0035, CVE-2007-0870, CVE-2007-1202

Release Date

15 Feb 2007

Last Change

09 May 2007

Criticality

Extremely Critical

Solution Status

Vendor Patch

Software

Microsoft Office 2000
Microsoft Office 2003 Professional Edition
Microsoft Office 2003 Small Business Edition
Microsoft Office 2003 Standard Edition
Microsoft Office 2003 Student and Teacher Edition
Microsoft Office 2004 for Mac
Microsoft Office Word Viewer 2003
Microsoft Office XP
Microsoft Word 2000
Microsoft Word 2002
Microsoft Word 2003
Microsoft Works Suite 2004
Microsoft Works Suite 2005
Microsoft Works Suite 2006

Where

From remote

Impact
System access

This covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user.

Description

Some vulnerabilities have been reported in Microsoft Word, which can be exploited by malicious people to compromise a user's system.

1) An unspecified error within the handling of data in arrays can be exploited via a specially crafted Word document.

2) An unspecified error when handling objects in Word Document streams can be exploited to cause memory corruption via a specially crafted Word document.

NOTE: This vulnerability is currently being actively exploited.

3) An unspecified error when processing certain rich text (RTF) properties can be exploited to cause memory corruption via a specially crafted file.

Successful exploitation of the vulnerabilities allows execution of arbitrary code.

Solution

Apply patches.

Microsoft Word 2000 (Office SP3):
http://www.microsoft.com/downloads/details.aspx?FamilyId=F25020F5-17C7-4A60-9088-944FFACB5F19

Microsoft Word 2002 (Office SP3)
http://www.microsoft.com/downloads/details.aspx?FamilyId=0FE4F405-A568-4F15-B2C6-02D4A4B58E43

Microsoft Word 2003 (Office SP2):
http://www.microsoft.com/downloads/details.aspx?FamilyId=6870245D-4618-4504-BFFC-878635267059

Microsoft Word Viewer 2003:
http://www.microsoft.com/downloads/details.aspx?FamilyId=24547C65-C29A-4D0A-A015-F3F08B24331F

Microsoft Office 2004 for Mac:
http://www.microsoft.com/mac

Microsoft Works Suite 2004:
http://www.microsoft.com/downloads/details.aspx?FamilyId=0FE4F405-A568-4F15-B2C6-02D4A4B58E43

Microsoft Works Suite 2005:
http://www.microsoft.com/downloads/details.aspx?FamilyId=0FE4F405-A568-4F15-B2C6-02D4A4B58E43

Microsoft Works Suite 2006:
http://www.microsoft.com/downloads/details.aspx?FamilyId=0FE4F405-A568-4F15-B2C6-02D4A4B58E43

Reported by

1) Reported by the vendor.
2) Discovered as a 0-day.
3) Discovered by an anonymous person and reported via iDefense Labs.

Original Advisory

MS07-024 (KB934232):
http://www.microsoft.com/technet/security/Bulletin/MS07-024.mspx

Microsoft:
http://www.microsoft.com/technet/security/advisory/933052.mspx

iDefense Labs:
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=525