| Last Updated Date | Jan 07, 2010 |
| Release Date | Dec 08, 2009 |
| Severity | High |
| Impact | System Compromise: Remote attackers can gain control of vulnerable systems. |
| Description | This indicates an attack attempt against a memory corruption vulnerability in Microsoft WordPad and Office.
The vulnerability is caused by an error when the vulnerable software handles a malicious .DOC file. It allows a remote attacker to execute arbitrary code by sending specially crafted Document file. |
| Affected Products | Microsoft Windows 2000 Service Pack 4 Windows XP Service Pack 2 and Windows XP Service Pack 3 Windows XP Professional x64 Edition Service Pack 2 Windows Server 2003 Service Pack 2 Windows Server 2003 x64 Edition Service Pack 2 Windows Server 2003 with SP2 for Itanium-based Systems Office Software and Components Microsoft Office Word 2002 Service Pack 3 Microsoft Office Word 2003 Service Pack 3 Microsoft Works 8.5 Microsoft Office Converter Pack |
| Recommended Actions | Apply patch, available from the web site:
http://www.microsoft.com/technet/security/Bulletin/MS09-073.mspx |
| Common Vulnerabilities and Exposures (CVE) | http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2506
|
| Microsoft Bulletin ID | MS09-073 http://www.microsoft.com/technet/security/Bulletin/MS09-073.mspx |