This application requires Javascript for optimal performance.

MS.Office.Art.Drawing.Remote.Code.Execution

Release Date

Oct 14, 2009

Severity

critical

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attempt to exploit a remote code execution vulnerability in MSO.DLL which affects Microsoft Office.

The vulnerability is caused by an error that occurs when the vulnerable software handles malicious Office Art drawing containers in Excel/Word file. It allows a remote attacker to execute arbitrary code via sending a crafted Excel/Word file.

Affected Products

Microsoft Office 2000
Microsoft Office XP

Recommended Actions

Apply the most recent upgrade or patch from the vendor.
http://www.microsoft.com/technet/security/Bulletin/MS09-062.mspx

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2009-2528

Reference/s

http://technet.microsoft.com/en-us/security/bulletin/MS09-062.mspx (MS-ID)

Reference: VID-17812