MS.Office.Drawing.Shapes.Memory

NameMS.Office.Drawing.Shapes.Memory.Corruption
Last Updated DateJan 12, 2010
Release DateAug 13, 2009
SeverityCritical
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
DescriptionThis indicates an attack attempt against a code execution vulnerability in Microsoft Office.

The vulnerability is caused by an error when the vulnerable software handles a specially crafted Office file. It allows a remote attacker to execute arbitrary code.
Affected ProductsMicrosoft Office 2000 Service Pack 3
Microsoft Office XP Service Pack 3
Microsoft Office 2003 Service Pack 2
Microsoft Office Excel Viewer 2003
Microsoft Office Excel Viewer 2003 Service Pack 3
Microsoft Office 2004 for Mac
Recommended ActionsApply patch, available from the web site:
http://www.microsoft.com/technet/security/bulletin/MS08-016.mspx
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0118
Microsoft Bulletin IDMS08-016   http://www.microsoft.com/technet/security/Bulletin/MS08-016.mspx
Reference/shttp://www.vupen.com/english/advisories/2008/0848 (FrSIRT)
http://www.milw0rm.com/exploits/5320
Reference: VID-15471