Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.901166
Categoría:Windows : Microsoft Bulletins
Título:Microsoft Office Remote Code Execution Vulnerabilities (2423930)
Resumen:This host is missing a critical security update according to; Microsoft Bulletin MS10-087.
Descripción:Summary:
This host is missing a critical security update according to
Microsoft Bulletin MS10-087.

Vulnerability Insight:
Multiple flaws are caused by,

- a stack overflow error when processing malformed Rich Text Format data.

- a memory corruption error when processing Office Art Drawing records in
Office files.

- a memory corruption error when handling drawing exceptions.

- a memory corruption error when handling SPID data in Office documents.

- an error when loading certain libraries from the current working directory.

Vulnerability Impact:
Successful exploitation could allow attackers to execute arbitrary code.

Affected Software/OS:
- Microsoft Office XP Service Pack 3

- Microsoft Office 2003 Service Pack 3

- Microsoft Office 2007 Service Pack 2

- Microsoft Office 2010

Solution:
The vendor has released updates. Please see the references for more information.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2010-3333
BugTraq ID: 44652
http://www.securityfocus.com/bid/44652
Cert/CC Advisory: TA10-313A
http://www.us-cert.gov/cas/techalerts/TA10-313A.html
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=880
Microsoft Security Bulletin: MS10-087
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-087
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11931
http://www.securitytracker.com/id?1024705
http://secunia.com/advisories/38521
http://secunia.com/advisories/42144
http://securityreason.com/securityalert/8293
http://www.vupen.com/english/advisories/2010/2923
Common Vulnerability Exposure (CVE) ID: CVE-2010-3334
BugTraq ID: 44656
http://www.securityfocus.com/bid/44656
Bugtraq: 20101109 Secunia Research: Microsoft Office Drawing Shape Container Parsing Vulnerability (Google Search)
http://www.securityfocus.com/archive/1/514699/100/0/threaded
http://secunia.com/secunia_research/2010-4/
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11439
Common Vulnerability Exposure (CVE) ID: CVE-2010-3335
BugTraq ID: 44659
http://www.securityfocus.com/bid/44659
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11739
Common Vulnerability Exposure (CVE) ID: CVE-2010-3336
BugTraq ID: 44660
http://www.securityfocus.com/bid/44660
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11947
Common Vulnerability Exposure (CVE) ID: CVE-2010-3337
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11929
CopyrightCopyright (C) 2010 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.