This application requires Javascript for optimal performance.

MS.Publisher.Pubconv.dll.Pointer.Overwrite.Memory.Corruption

Release Date

Jan 19, 2012

Severity

critical

Impact

System Compromise: Remote attackers can gain control of vulnerable systems

Description

This indicates an attack attempt to exploit a Memory Corruption vulnerability in Microsoft Office Publisher.

The vulnerability is due to an error when the vulnerable software handles a maliciously crafted .pub file. As a result, a remote attacker may be able to execute arbitrary code within the context of the application, via a crafted .pub file.

Affected Products

Microsoft Office Publisher 2003
Microsoft Office Publisher 2007

Recommended Actions

Apply the most recent upgrade or patch from the vendor.
http://technet.microsoft.com/en-us/security/bulletin/ms11-091/

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2011-1508

Reference/s

http://technet.microsoft.com/en-us/security/bulletin/MS11-091.mspx (MS-ID)

Reference: VID-30727