MS.Word.PRCDATA.Code.Execution

Last Updated DateAug 04, 2009
Release DateJun 11, 2009
SeverityCritical
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
DescriptionThis indicates a possible attack against a buffer-overflow vulnerability in Microsoft Word.

The vulnerability is due to the software's inability to properly handle Word files that have a malformed record. A remote attacker may exploit this to execute arbitrary code.
Affected ProductsMicrosoft Office Word 2000-2007
Recommended ActionsApply the patch, available at the vendor's web site:
http://www.microsoft.com/technet/security/bulletin/ms09-027.mspx
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0563
Microsoft Bulletin IDMS09-027   http://www.microsoft.com/technet/security/Bulletin/MS09-027.mspx
Reference/shttp://www.securityfocus.com/bid/35188 (BugTraq)
Reference: VID-17513