Name:
MS.Word.RTF.Drawing.Object.Integer.Overflow
Released Date:
May 14 2008
Severity:
critical
CVE:
2008-1091
MS Bulletin:
ms08-026

FortiGuard Center > Vulnerability Encyclopedia


In-Depth Analysis

Description
This indicates an attempt to exploit an integer-overflow vulnerability in Microsoft Word.

The vulnerabilities are caused by an error that occurs when the vulnerable software handles a malicious RTF file. It allows a remote attacker to execute arbitrary code via a crafted RTF file.
 
Impact
System compromise: remote code execution.
 
Affected Products
Microsoft Office 2000 Service Pack 3
Microsoft Office XP Service Pack 3
Microsoft Office 2003 Service Pack 2
Microsoft Office 2003 Service Pack 3
2007 Microsoft Office System
Microsoft Outlook 2007
2007 Microsoft Office System Service Pack 1
Microsoft Outlook 2007 Service Pack 1
Microsoft Word Viewer 2003
Microsoft Word Viewer 2003 Service Pack 3
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Service Pack 1
Microsoft Office 2004 for Mac
Microsoft Office 2008 for Mac
Aliases
References
http://www.microsoft.com/technet/security/Bulletin/ms08-026.mspx
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-1091
http://www.zerodayinitiative.com/advisories/ZDI-08-023/
Recommended Actions
Apply the patch available from the web site:
http://www.microsoft.com/technet/security/bulletin/ms08-026.mspx

 
 
SITE MAP  |  LEGAL NOTICES

      © 2003 FORTINET INC. ALL RIGHTS RESERVED