This application requires Javascript for optimal performance.

MS.Office.Component.Insecure.Library.Loading

Release Date

Jan 05, 2012

Severity

critical

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt to exploit a Remote Code Execution vulnerability in Microsoft Office.

The vulnerability is due to the way Microsoft Office loads DLL files. An attacker can exploit this by tricking an unsuspecting user into accessing a malicious Office file. Successful attacks may allow the attacker to execute arbitrary code with the authenticated privileges of the user.

Affected Products

Microsoft Office XP Service Pack 3
Microsoft Office 2003 Service Pack 3
Microsoft Office 2007 Service Pack 2
Microsoft Office 2004 for Mac
Microsoft Office 2008 for Mac
Open XML File Format Converter for Mac

Recommended Actions

Apply the most recent upgrade or patch from the vendor.
http://technet.microsoft.com/en-us/security/bulletin/ms11-023

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2011-0107

Reference/s

http://technet.microsoft.com/en-us/security/bulletin/ms11-023.mspx (MS-ID)

Reference: VID-26532