Ravens PHP Scripts

Extremely Critical! Microsoft Word 2000 Unspecified Code Execution Vulnerability
Date: Tuesday, September 05, 2006 @ 07:21:01 CDT
Topic: Security


TITLE: Microsoft Word 2000 Unspecified Code Execution Vulnerability

SECUNIA ADVISORY ID: SA21735

VERIFY ADVISORY: http://secunia.com/advisories/21735/

CRITICAL: Extremely critical

IMPACT: System access

WHERE: >From remote

SOFTWARE:
Microsoft Word 2000 - http://secunia.com/product/2149/
Microsoft Office 2000 - http://secunia.com/product/24/
DESCRIPTION: A vulnerability has been reported in Microsoft Word 2000, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an unspecified error when processing Word documents. This can be exploited to execute arbitrary code when a malicious document is opened. The vulnerability is reported in Microsoft Word 2000 running on Windows 2000. Other versions may also be affected.

NOTE: The vulnerability is being actively exploited.


SOLUTION: Do not open untrusted Office documents.

PROVIDED AND/OR DISCOVERED BY: Discovered in the wild as a 0-day.

OTHER REFERENCES: Symantec: - http://www.symantec.com/enterprise/security_response/weblog/2006/09/new_tricks_with_old_software.html








This article comes from Ravens PHP Scripts
https://www.ravenphpscripts.com

The URL for this story is:
https://www.ravenphpscripts.com/modules.php?name=News&file=article&sid=2377