 |
Name:
MS.Word.RTF.Drawing.Object.Integer.Overflow
|
Released Date:
May 14 2008
|
Severity:
critical
|
CVE:
2008-1091
|
MS Bulletin:
ms08-026
|
|
|
|
|
|
|
FortiGuard Center
> Vulnerability Encyclopedia

In-Depth Analysis
|
Description
|
This indicates an attempt to exploit an integer-overflow vulnerability in Microsoft Word.
The vulnerabilities are caused by an error that occurs when the vulnerable software handles a malicious RTF file. It allows a remote attacker to execute arbitrary code via a crafted RTF file.
|
|
|
|
Impact
|
|
System compromise: remote code execution.
|
|
|
|
Affected Products
|
Microsoft Office 2000 Service Pack 3 Microsoft Office XP Service Pack 3 Microsoft Office 2003 Service Pack 2 Microsoft Office 2003 Service Pack 3 2007 Microsoft Office System Microsoft Outlook 2007 2007 Microsoft Office System Service Pack 1 Microsoft Outlook 2007 Service Pack 1 Microsoft Word Viewer 2003 Microsoft Word Viewer 2003 Service Pack 3 Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Service Pack 1 Microsoft Office 2004 for Mac Microsoft Office 2008 for Mac
|
|
Aliases
|
|
References
|
http://www.microsoft.com/technet/security/Bulletin/ms08-026.mspx
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-1091
http://www.zerodayinitiative.com/advisories/ZDI-08-023/
|
|
Recommended Actions
|
Apply the patch available from the web site: http://www.microsoft.com/technet/security/bulletin/ms08-026.mspx
|
|