This application requires Javascript for optimal performance.

MS.Word.Linked.Objects.Memory.Corruption

Release Date

Aug 11, 2010

Severity

critical

Impact

System compromise
Denial of service

Description

This indicates a possible attack against a memory-corruption vulnerability in Microsoft Word.

The vulnerability is caused by the vulnerable software's inability to properly handle malformed data in Word documents. An attacker may exploit this to execute arbitrary code.

Affected Products

Microsoft Office Word 2002 Service Pack 3
Microsoft Office Word 2003 Service Pack 3
Microsoft Office Word Viewer

Recommended Actions

Apply the update supplied by the vendor:
http://www.microsoft.com/technet/security/Bulletin/ms10-056.mspx

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2010-1903

Reference/s

http://technet.microsoft.com/en-us/security/bulletin/ms10-056.mspx (MS-ID)
http://www.zerodayinitiative.com/advisories/ZDI-10-151

Reference: VID-24069