Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.900065
Kategorie:Windows : Microsoft Bulletins
Titel:WordPad and Office Text Converter Memory Corruption Vulnerability (960477)
Zusammenfassung:This host is missing a critical security update according to Microsoft; Bulletin MS09-010.
Beschreibung:Summary:
This host is missing a critical security update according to Microsoft
Bulletin MS09-010.

Vulnerability Insight:
- Input validation error when parsing document files i.e. Office files, RTF,
Wordperfect files or Write files.

Vulnerability Impact:
Successful exploitation will let the attacker craft malicious arbitrary codes
into the files and can trick the user to open those crafted documents which
may lead to remote arbitrary code execution inside the context of the affected system.

Affected Software/OS:
WordPad on MS Windows 2K/XP/2K3

MS Office 2000 Word Service Pack 3

MS Office XP Word Service Pack 3

MS Office Converters Pack

Solution:
The vendor has released updates. Please see the references for more information.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2008-4841
BugTraq ID: 31399
http://www.securityfocus.com/bid/31399
BugTraq ID: 32718
http://www.securityfocus.com/bid/32718
Cert/CC Advisory: TA09-104A
http://www.us-cert.gov/cas/techalerts/TA09-104A.html
https://www.exploit-db.com/exploits/6560
http://milw0rm.com/sploits/2008-crash.doc.rar
Microsoft Security Bulletin: MS09-010
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-010
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6050
http://securitytracker.com/id?1021376
http://secunia.com/advisories/32997
http://securityreason.com/securityalert/4711
http://www.vupen.com/english/advisories/2008/3390
http://www.vupen.com/english/advisories/2009/1024
Common Vulnerability Exposure (CVE) ID: CVE-2009-0087
http://osvdb.org/53662
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5799
http://www.securitytracker.com/id?1022043
Common Vulnerability Exposure (CVE) ID: CVE-2009-0088
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=782
http://osvdb.org/53663
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5736
Common Vulnerability Exposure (CVE) ID: CVE-2009-0235
BugTraq ID: 34470
http://www.securityfocus.com/bid/34470
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=783
http://osvdb.org/53664
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5893
CopyrightCopyright (C) 2008 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.