Microsoft Word Unspecified Memory Corruption Vulnerability

Posted on Wednesday, December 06, 2006 @ 05:54:16 CST in Security
by Raven

SECUNIA ADVISORY ID: SA23232

VERIFY ADVISORY: http://secunia.com/advisories/23232/

CRITICAL: Extremely critical

IMPACT: System access

DESCRIPTION: A vulnerability has been reported in Microsoft Word, which potentially can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an unspecified error in the handling of Word documents can be exploited to cause a memory corruption. Successful exploitation may allow execution of arbitrary code.

SOFTWARE:

Microsoft Works Suite 2006 - http://secunia.com/product/8712/
Microsoft Works Suite 2005 - http://secunia.com/product/8711/
Microsoft Works Suite 2004 - http://secunia.com/product/3897/
Microsoft Word 2003 Viewer - http://secunia.com/product/5523/
Microsoft Word 2003 - http://secunia.com/product/4908/
Microsoft Word 2002 - http://secunia.com/product/2150/
Microsoft Word 2000 - http://secunia.com/product/2149/
Microsoft Office X for Mac - http://secunia.com/product/2610/
Microsoft Office 2004 for Mac - http://secunia.com/product/8713/
Microsoft Office 2003 Student and Teacher Edition - http://secunia.com/product/2278/
Microsoft Office 2003 Standard Edition - http://secunia.com/product/2275/
Microsoft Office 2003 Small Business Edition - http://secunia.com/product/2277/
Microsoft Office 2003 Professional Edition - http://secunia.com/product/2276/
Microsoft Office 2000 - http://secunia.com/product/24/
Microsoft Office XP - http://secunia.com/product/23/

SOLUTION: Do not open or save untrusted Word documents.

PROVIDED AND/OR DISCOVERED BY: Discovered as a 0-day.

ORIGINAL ADVISORY: Microsoft:
http://www.microsoft.com/technet/security/advisory/929433.mspx
http://blogs.technet.com/msrc/archive/2006/12/06/microsoft-security-advisory-929433-posted.aspx