Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News >

July 10th, 2006, 07:49 GMT · By

Microsoft Office Users Vulnerable, Again

SHARE:

Adjust text size:


Just before Microsoft monthly release of security patches, another office vulnerability has been brought to the attention of the public. As the product has proven a collection of security holes in the past,
another surfaced vulnerability just adds to the pile. This time around it is related to the way in which the office application manages the LsCreateLine() Function.

The flaw could allow a remote user to cause the execution of arbitrary code on the target system. The vulnerability can be exploited via a malicious Word document. When the user executes such a file he unknowingly triggers a memory access error in the LsCreateLine() function in mso.dll, paving the way for the execution of arbitrary code. The flaw is triggered by the inability of one of the functions in mso.dll, namely the exported function LsCreateLine(), that contains a boundary error, to manage a specially created file and it leads to invalid memory access and arbitrary overwrites. After just 4 bytes of arbitrary memory are overwritten, code executions become possible. The worrying aspect of this vulnerability is that it requires no interaction from the user, as it takes place on file load. As of now it has been established that the affected versions are Microsoft Word 2003, 2002 and 2000.

As of yet Microsoft's representatives have not commented in any way the newly found vulnerability. A fix is not available at this time.

TELL US WHAT YOU THINK:

1,062 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Microsoft's Vulnerabilities Already Exploited by Reverse Engineering

7 more Microsoft Patches

Microsoft Internet Explorer Heap Overflow Vulnerability

Month of Browser Bugs

Method to Better Predict Software Vulnerabilities

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM