This application requires Javascript for optimal performance.

MS.Office.Word.Code.Execution

Release Date

Dec 15, 2011

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt against an Remote Code Execution vulnerability in Microsoft Word.

The vulnerability is caused by an error when the vulnerable software handles a specially crafted ".docx" file. It allows a remote attacker to execute arbitrary code.

Affected Products

Microsoft Office 2007 Service Pack 2 and Microsoft Office 2007 Service Pack 3
Microsoft Office 2010 and Microsoft Office 2010 Service Pack 1 (32-bit editions)
Microsoft Office 2010 and Microsoft Office 2010 Service Pack 1 (64-bit editions)
Microsoft Office for Mac 2011

Recommended Actions

Apply the most recent upgrades or patches from the vendor:
http://www.microsoft.com/technet/security/Bulletin/MS11-089.mspx

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2011-1983

Reference/s

http://technet.microsoft.com/en-us/security/bulletin/MS11-089.mspx (MS-ID)
http://www.securityfocus.com/bid/50956 (BugTraq)

Reference: VID-30594