Release DateAug 15, 2008 |
Severitycritical |
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems. |
DescriptionThis indicates an attack attempt against a buffer overflow vulnerability in Microsoft Office Filters.The vulnerability is caused by an error that occurs when the vulnerable software handles a malicious Apple PICT / QuickDraw image file. It allows a remote attacker to execute arbitrary code by luring the victim to import the file in Office documents. |
Affected ProductsMicrosoft Office 2000 Service Pack 3Microsoft Office XP Service Pack 3 Microsoft Office 2003 Service Pack 2 Microsoft Office Project 2002 Service Pack 1 Microsoft Office Converter Pack Microsoft Works 8 |
Recommended ActionsApply the latest update from the vendor. |
Coverage IPS
VCM |
Common Vulnerabilities and Exposures (CVE)CVE-2008-3021CVE-2006-5992 |
Reference/shttp://developer.apple.com/documentation/Carbon/Reference/QuickDraw_Ref/Reference/reference.htmlhttp://www.microsoft.com/technet/security/Bulletin/ms08-044.mspx (MS-ID) http://www.securityfocus.com/bid/30598 (BugTraq) |