| Last Updated Date | Dec 15, 2009 |
| Release Date | Nov 12, 2009 |
| Severity | High |
| Impact | System Compromise: Remote attackers can gain control of vulnerable systems. |
| Description | This indicates an attack attempt against a memory corruption vulnerability in Microsoft Office Word.
The vulnerability is caused by an error when the vulnerable software handles a malicious .DOC file. It allows a remote attacker to execute arbitrary code by sending specially crafted Document file. |
| Affected Products | Microsoft Office Word 2002 Service Pack 3 Microsoft Office Word 2003 Service Pack 3 Microsoft Office 2004 for Mac Microsoft Office 2008 for Mac Open XML File Format Converter for Mac Microsoft Office Word Viewer 2003 Service Pack 3 Microsoft Office Word Viewer |
| Recommended Actions | Apply patch, available from the web site:
http://www.microsoft.com/technet/security/Bulletin/MS09-068.mspx |
| Common Vulnerabilities and Exposures (CVE) | http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3135
|
| Microsoft Bulletin ID | MS09-068 http://www.microsoft.com/technet/security/Bulletin/MS09-068.mspx |