MS.Office.PICT.Heap.Corruption

Release DateAug 15, 2008
SeverityCritical
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
DescriptionThis indicates a possible attempt to exploit a heap corruption vulnerability in Microsoft Office.

The vulnerability is caused by an error that occurs when the vulnerable software handles an imported PICT file. A remote attacker may exploit this to
execute arbitrary code via a crafted PICT file.
Affected ProductsMicrosoft Office 2000 Service Pack 3
Microsoft Office XP Service Pack 3
Microsoft Office 2003 Service Pack 2
Microsoft Office Project 2002 Service Pack 1
Microsoft Office Converter Pack
Microsoft Works 8
Recommended ActionsRefer to the vendor's web site for suggested workground.
http://www.microsoft.com/technet/security/Bulletin/ms08-044.mspx
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2006-1307
http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-3018
Microsoft Bulletin IDMS08-044   http://www.microsoft.com/technet/security/Bulletin/ms08-044.mspx
Reference: VID-15785