This application requires Javascript for optimal performance.

MS.Word.Document.Stream.Handling.Code.Execution

Release Date

Jul 12, 2007

Severity

critical

Impact

The execution of arbitrary code on the system.

Description

This indicates a possible exploit of a memory-corruption vulnerability in Microsoft Word.

A memory corruption error may occur when handling a specially crafted document, which could lead to the execution of arbitrary code on the affected system.

Affected Products

Microsoft Office 2000
Microsoft Office XP
Microsoft Word 2000
Microsoft Word 2002

Recommended Actions

Apply the appropriate patch supplied by the vendor:
http://www.microsoft.com/technet/security/bulletin/ms07-024.mspx

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2007-0870

Reference/s

http://technet.microsoft.com/en-us/security/bulletin/MS07-024.mspx (MS-ID)
http://www.securityfocus.com/bid/22567 (BugTraq)

Reference: VID-14173