MS.Word.SPRM.Code.Execution

Last Updated DateJul 23, 2009
Release DateJun 11, 2009
SeverityCritical
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
DescriptionThis indicates a possible attack against a buffer-overflow vulnerability in Microsoft Word.

The vulnerability is due to the software's inability to properly handle Word files that have a malformed record. A remote attacker may exploit this to execute arbitrary code.
Affected ProductsMicrosoft Office Word 2000-2007
Recommended ActionsApply the patch, available at the vendor's web site:
http://www.microsoft.com/technet/security/bulletin/ms09-027.mspx
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0565
Microsoft Bulletin IDMS09-027   http://www.microsoft.com/technet/security/Bulletin/MS09-027.mspx
Reference/shttp://www.securityfocus.com/bid/35190 (BugTraq)
Reference: VID-17514