English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Microsoft Office Word Two Vulnerabilities


Secunia ID

SA35377

CVE-ID

CVE-2009-0563, CVE-2009-0565

Release Date

09 Jun 2009

Last Change

11 Jun 2009

Criticality

Highly Critical

Solution Status

Vendor Patch

Software

Microsoft Office 2000
Microsoft Office 2003 Professional Edition
Microsoft Office 2003 Small Business Edition
Microsoft Office 2003 Standard Edition
Microsoft Office 2003 Student and Teacher Edition
Microsoft Office 2004 for Mac
Microsoft Office 2007
Microsoft Office 2008 for Mac
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats
Microsoft Office Word 2007
Microsoft Office Word Viewer
Microsoft Office Word Viewer 2003
Microsoft Office XP
Microsoft Open XML File Format Converter for Mac
Microsoft Word 2000
Microsoft Word 2002
Microsoft Word 2003

Where

From remote

Impact
System access

This covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user.

Description

Two vulnerabilities have been reported in Microsoft Office Word, which can be exploited by malicious people to compromise a user's system.

1) A boundary error when parsing invalid length fields in certain records can be exploited to cause a stack-based buffer overflow via a specially crafted Word document.

2) Another boundary error when parsing certain records can be exploited to cause a buffer overflow via a specially crafted Word document.

Successful exploitation of the vulnerabilities may allow execution of arbitrary code.

Solution

Apply patches.

Microsoft Office Word 2000 SP3:
http://www.microsoft.com/downloads/details.aspx?familyid=3663e9f2-a952-4238-b902-90b5b09feb38

Microsoft Office Word 2002 SP3:
http://www.microsoft.com/downloads/details.aspx?familyid=f1323be1-15f2-491b-abae-c03ba1394398

Microsoft Office Word 2003 SP3:
http://www.microsoft.com/downloads/details.aspx?familyid=7cbc2587-2c8c-49b4-9f40-e4cdccb61ecd

Microsoft Office Word 2007 SP1:
http://www.microsoft.com/downloads/details.aspx?familyid=7e205108-4c28-4cab-a4d0-4ed3fd696473

Microsoft Office Word 2007 SP2:
http://www.microsoft.com/downloads/details.aspx?familyid=7e205108-4c28-4cab-a4d0-4ed3fd696473

Microsoft Office 2004 for Mac:
http://www.microsoft.com/downloads/details.aspx?FamilyID=5557bfb7-ebb4-4c42-8042-41e830c4e550

Microsoft Office 2008 for Mac:
http://www.microsoft.com/downloads/details.aspx?FamilyID=58326da2-eb75-4b42-b1bc-e70319defb58

Open XML File Format Converter for Mac:
http://www.microsoft.com/downloads/details.aspx?FamilyID=9d6d9eaa-8442-4184-8886-faab2803bde6

Microsoft Office Word Viewer 2003 SP3:
http://www.microsoft.com/downloads/details.aspx?familyid=82980a40-f10c-4f02-b06c-3a12d4434a6b

Microsoft Office Word Viewer:
http://www.microsoft.com/downloads/details.aspx?familyid=82980a40-f10c-4f02-b06c-3a12d4434a6b

Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1:
http://www.microsoft.com/downloads/details.aspx?familyid=63bd8f14-e736-46ce-af66-d30f17461e5a

Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2:
http://www.microsoft.com/downloads/details.aspx?familyid=63bd8f14-e736-46ce-af66-d30f17461e5a

Reported by

1) ling & wushi of team509, reported via ZDI
2) Nicolas Joly, Vupen Security

Original Advisory

MS09-027 (KB969514, KB969600, KB969602, KB969603, KB969604, KB969613, KB969614, KB969661, KB971822, KB971824):
http://www.microsoft.com/technet/security/Bulletin/MS09-027.mspx

Vupen Security:
http://www.vupen.com/english/advisories/2009/1546

ZDI:
http://www.zerodayinitiative.com/advisories/ZDI-09-035/