MS.Word.Text.Converter.Memory.Corruption

Last Updated DateJan 07, 2010
Release DateDec 08, 2009
SeverityHigh
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
DescriptionThis indicates an attack attempt against a memory corruption vulnerability in Microsoft WordPad and Office.

The vulnerability is caused by an error when the vulnerable software handles a malicious .DOC file. It allows a remote attacker to execute arbitrary code by sending specially crafted Document file.
Affected ProductsMicrosoft Windows 2000 Service Pack 4
Windows XP Service Pack 2 and Windows XP Service Pack 3
Windows XP Professional x64 Edition Service Pack 2
Windows Server 2003 Service Pack 2
Windows Server 2003 x64 Edition Service Pack 2
Windows Server 2003 with SP2 for Itanium-based Systems
Office Software and Components
Microsoft Office Word 2002 Service Pack 3
Microsoft Office Word 2003 Service Pack 3
Microsoft Works 8.5
Microsoft Office Converter Pack
Recommended ActionsApply patch, available from the web site:

http://www.microsoft.com/technet/security/Bulletin/MS09-073.mspx
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2506
Microsoft Bulletin IDMS09-073   http://www.microsoft.com/technet/security/Bulletin/MS09-073.mspx
Reference: VID-18019