MS.Word.Nfib.Memory.Corruption

Last Updated DateDec 15, 2009
Release DateNov 12, 2009
SeverityHigh
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
DescriptionThis indicates an attack attempt against a memory corruption vulnerability in Microsoft Office Word.

The vulnerability is caused by an error when the vulnerable software handles a malicious .DOC file. It allows a remote attacker to execute arbitrary code by sending specially crafted Document file.
Affected ProductsMicrosoft Office Word 2002 Service Pack 3
Microsoft Office Word 2003 Service Pack 3
Microsoft Office 2004 for Mac
Microsoft Office 2008 for Mac
Open XML File Format Converter for Mac
Microsoft Office Word Viewer 2003 Service Pack 3
Microsoft Office Word Viewer
Recommended ActionsApply patch, available from the web site:

http://www.microsoft.com/technet/security/Bulletin/MS09-068.mspx
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3135
Microsoft Bulletin IDMS09-068   http://www.microsoft.com/technet/security/Bulletin/MS09-068.mspx
Reference: VID-17933