Microsoft
Office Malformed BMP Filter Vulnerability
Date Discovered:
08/12/2008
Severity:
High
Applications Affected:
Microsoft Office 2000
SP3
Microsoft Office XP SP3
Microsoft Office 2003 SP2
Microsoft Office Project 2002 SP1
Microsoft Office Converter Pack
Microsoft Works 8
Synopsis
Microsoft
Office is prone to a Malformed BMP Filter Vulnerability. This
vulnerability exists in the way that Microsoft Office handles a
BMP-format image file. The vulnerability could be exploited when a
Microsoft Office application opens a specially crafted BMP-format image
file.
Malformed BMP Filter vulnerability exists in
Microsoft Office and could be exploited when a specially crafted
BMP-format image file is opened by any of the affected Microsoft Office
applications. Such a file might be included in an e-mail attachment or
hosted on a malicious Web site.
When Microsoft Office opens a specially crafted BMP image file, it may
corrupt system memory in such a way that an attacker could execute
arbitrary code. An attacker who successfully exploited this
vulnerability could take complete control of the affected system.
“iPolicy is one of the most visionary firewall vendors in the firewall Magic Quadrant. Its architecture of a central session processing engine and multiple content blades that are able to block based on signatures, rules and so on is the closest to the network security ideal.”
Greg Young, John Pescatore
Magic Quadrant for Network Firewalls, 2H04, Gartner