Microsoft
Word Cascading Style Sheet Vulnerability
Date Discovered:
05/13/2008
Severity:
High
Applications Affected:
Microsoft Office 2000
SP3
Microsoft Office XP SP3
Microsoft Office 2003 SP2
Microsoft Office 2003 SP3
Microsoft Office System 2007
Microsoft Office System 2007 SP1
Microsoft Word Viewer 2003
Microsoft Word Viewer 2003 SP3
Microsoft Office 2004 for Mac
Microsoft Office 2008 for Mac
Synopsis
Microsoft
word is prone to a Cascading Style Sheet (CSS) vulnerability. This
vulnerability exists in the way that Microsoft Word handles specially
crafted Word files.
The vulnerability is caused by a memory
handling error when processing CSS values in a specially crafted Word
file. The error may corrupt system memory in such a way that an
attacker could execute arbitrary code. he vulnerability could allow
remote code execution if a user opens a specially crafted Word file
that includes a malformed CSS value. An attacker who successfully
exploited this vulnerability could take complete control of an affected
system.
An attacker who successfully exploited this vulnerability could take
complete control of an affected system. An attacker could then install
programs, view, change, delete data, or create new accounts with full
user rights.
“iPolicy is one of the most visionary firewall vendors in the firewall Magic Quadrant. Its architecture of a central session processing engine and multiple content blades that are able to block based on signatures, rules and so on is the closest to the network security ideal.”
Greg Young, John Pescatore
Magic Quadrant for Network Firewalls, 2H04, Gartner