Release DateJan 19, 2012 |
Severitycritical |
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems |
DescriptionThis indicates an attack attempt to exploit a Memory Corruption vulnerability in Microsoft Office Publisher.The vulnerability is due to an error when the vulnerable software handles a maliciously crafted .pub file. As a result, a remote attacker may be able to execute arbitrary code within the context of the application, via a crafted .pub file. |
Affected ProductsMicrosoft Office Publisher 2003Microsoft Office Publisher 2007 |
Recommended ActionsApply the most recent upgrade or patch from the vendor.http://technet.microsoft.com/en-us/security/bulletin/ms11-091/ |
Coverage IPS
VCM |
Common Vulnerabilities and Exposures (CVE)CVE-2011-1508 |
Reference/shttp://technet.microsoft.com/en-us/security/bulletin/MS11-091.mspx (MS-ID) |