Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.902265
Kategorie:Windows : Microsoft Bulletins
Titel:Microsoft Office Word Remote Code Execution Vulnerabilities (2293194)
Zusammenfassung:This host is missing a critical security update according to; Microsoft Bulletin MS10-079.
Beschreibung:Summary:
This host is missing a critical security update according to
Microsoft Bulletin MS10-079.

Vulnerability Insight:
The flaws are due to:

- An uninitialized pointer error when processing malformed data in a Word file

- An improper boundary check when processing certain data in a Word file

- An error when handling index values within a Word document

- A stack overflow error when processing malformed data within a Word
document

- An error when handling return values, bookmarks, pointers while parsing
a specially crafted Word

- A heap overflow error when handling malformed records within a Word file

- An error when handling indexes while parsing a specially crafted Word file

Vulnerability Impact:
Successful exploitation could allow attackers to execute arbitrary code by
tricking a user into opening a specially crafted word document.

Affected Software/OS:
- Microsoft Word 2010

- Microsoft Office Word Viewer

- Microsoft Office Word 2002 Service Pack 3

- Microsoft Office Word 2003 Service Pack 3

- Microsoft Office Word 2007 Service Pack 2

- Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Service Pack 2

Solution:
The vendor has released updates. Please see the references for more information.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2010-2747
Bugtraq: 20101014 VUPEN Security Research - Microsoft Office Word Uninitialized Pointer Vulnerability (CVE-2010-2747) (Google Search)
http://www.securityfocus.com/archive/1/514310/100/0/threaded
Cert/CC Advisory: TA10-285A
http://www.us-cert.gov/cas/techalerts/TA10-285A.html
Microsoft Security Bulletin: MS10-079
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-079
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7121
Common Vulnerability Exposure (CVE) ID: CVE-2010-2748
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7375
Common Vulnerability Exposure (CVE) ID: CVE-2010-2750
Bugtraq: 20101014 VUPEN Security Research - Microsoft Office Word Document Array Indexing Vulnerability (CVE-2010-2750) (Google Search)
http://www.securityfocus.com/archive/1/514292/100/0/threaded
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7582
Common Vulnerability Exposure (CVE) ID: CVE-2010-3214
Bugtraq: 20101014 VUPEN Security Research - Microsoft Office Word Document Stack Overflow Vulnerability (CVE-2010-3214) (Google Search)
http://www.securityfocus.com/archive/1/514302/100/0/threaded
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7322
Common Vulnerability Exposure (CVE) ID: CVE-2010-3215
Bugtraq: 20101014 VUPEN Security Research - Microsoft Office Word Return Value Handling Vulnerability (CVE-2010-3215) (Google Search)
http://www.securityfocus.com/archive/1/514295/100/0/threaded
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6974
Common Vulnerability Exposure (CVE) ID: CVE-2010-3216
Bugtraq: 20101014 VUPEN Security Research - Microsoft Office Word Bookmarks Invalid Pointer Vulnerability (CVE-2010-3216) (Google Search)
http://www.securityfocus.com/archive/1/514291/100/0/threaded
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7529
Common Vulnerability Exposure (CVE) ID: CVE-2010-3217
Bugtraq: 20101014 VUPEN Security Research - Microsoft Office Word Document Invalid Pointer Vulnerability (CVE-2010-3217) (Google Search)
http://www.securityfocus.com/archive/1/514298/100/0/threaded
Bugtraq: 20101223 Secunia Research: Microsoft Word LFO Parsing Double-Free Vulnerability (Google Search)
http://www.securityfocus.com/archive/1/515440/100/0/threaded
http://secunia.com/secunia_research/2010-76/
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6695
Common Vulnerability Exposure (CVE) ID: CVE-2010-3218
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7010
Common Vulnerability Exposure (CVE) ID: CVE-2010-3219
Bugtraq: 20101014 VUPEN Security Research - Microsoft Office Word BKF Objects Array Indexing Vulnerability (CVE-2010-3219) (Google Search)
http://www.securityfocus.com/archive/1/514305/100/0/threaded
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7019
Common Vulnerability Exposure (CVE) ID: CVE-2010-3220
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6792
Common Vulnerability Exposure (CVE) ID: CVE-2010-3221
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7032
CopyrightCopyright (C) 2010 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.