Name:
MS.Word.HTML.CSS.Double.Free
Released Date:
May 14 2008
Severity:
critical
CVE:
2008-1434
MS Bulletin:
ms08-026
Bugtraq:
29105

FortiGuard Center > Vulnerability Encyclopedia


In-Depth Analysis

Description
This indicates an attempt to exploit a double free vulnerability in Microsoft Word.

The vulnerabilities are caused by an error that occurs when the vulnerable software handles a malicious DOC file. A remote attacker may exploit this to execute arbitrary code via a crafted DOC file.
 
Impact
System compromise: remote code execution.
 
Affected Products
Microsoft Office 2000 Service Pack 3
Microsoft Office XP Service Pack 3
Microsoft Office 2003 Service Pack 2
Microsoft Office 2003 Service Pack 3
2007 Microsoft Office System
Microsoft Outlook 2007
2007 Microsoft Office System Service Pack 1
Microsoft Outlook 2007 Service Pack 1
Microsoft Word Viewer 2003
Microsoft Word Viewer 2003 Service Pack 3
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Service Pack 1
Microsoft Office 2004 for Mac
Microsoft Office 2008 for Mac
Aliases
References
http://www.microsoft.com/technet/security/Bulletin/ms08-026.mspx
http://www.securityfocus.com/bid/29105
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-1434
Recommended Actions
Apply the patch available from the following web site:
http://www.microsoft.com/technet/security/bulletin/ms08-026.mspx

 
 
SITE MAP  |  LEGAL NOTICES

      © 2003 FORTINET INC. ALL RIGHTS RESERVED