This application requires Javascript for optimal performance.

MS.RTF.Object.Package.Download.Attempt

Alias(es)

Microsoft.RTF.Object.Package.Download.Attempt

Release Date

Oct 10, 2006

Severity

medium

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt to exploit the Dialogue Spoofing Vulnerability in Microsoft Windows Object Packager.

The Windows Object Packager in Microsoft Windows XP SP1 and SP2 and Server 2003 SP1 and earlier does not properly handle file extensions that could allow remote attackers to execute arbitrary command by sending crafted file with embedded package object.

Affected Products

Microsoft Windows XP Service Pack 1
Microsoft Windows XP Service Pack 2
Microsoft Windows XP Professional x64 Edition
Microsoft Windows Server 2003
Microsoft Windows Server 2003 Service Pack 1
Microsoft Windows Server 2003 (Itanium)
Microsoft Windows Server 2003 SP1 (Itanium)
Microsoft Windows Server 2003 x64 Edition

Recommended Actions

Apply patch, available from the web site:
http://www.microsoft.com/technet/security/bulletin/MS06-065.mspx

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2006-4692

Reference/s

http://technet.microsoft.com/en-us/security/bulletin/MS06-065.mspx (MS-ID)
http://www.frsirt.com/english/advisories/2006/3984 (FrSIRT)

Reference: VID-13241