Home→Descriptions→SA30150
| Secunia ID | |
| CVE-ID | |
| Release Date |
13 May 2008 |
| Last Change |
14 May 2008 |
| Criticality | |
| Solution Status |
Vendor Patch |
| Software |
Microsoft Office 2000 |
| Where | |
| Impact |
System accessThis covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user. |
| Description |
A vulnerability has been reported in Microsoft Publisher, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an error in the object handler when parsing object header data. This can be exploited to corrupt memory via a specially crafted Publisher file. Successful exploitation may allow execution of arbitrary code. |
| Solution |
Apply patches. Microsoft Publisher 2000 SP3: Microsoft Publisher 2002 SP3: Microsoft Publisher 2003 SP2: Microsoft Publisher 2003 SP3: Microsoft Publisher 2007: Microsoft Publisher 2007 SP1: |
| Reported by |
cocoruder, Fortinet Security Research. |
| Original Advisory |
MS08-027 (KB951208): |