This application requires Javascript for optimal performance.

MS.WordPad.Embedded.COM.Code.Execution

Release Date

Mar 08, 2011

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates that a non-ActiveX COM object, such as OutlookExpress.AddressBook COM control, InstallEngine COM control, or Sysmon.3 COM contro, is embedded into the OLE section of a WordPad RTF document. It can result in arbitrary code execution or a crash.

Affected Products

Microsoft WordPad

Recommended Actions

Currently we are not aware of any patches supplied by the vendor for this issue.

Coverage

IPS
VCM

Reference/s

https://strikecenter.bpointsys.com/bps/advisory/BPS-2006-0001

Reference: VID-25373