| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.902178 |
| Category: | Windows : Microsoft Bulletins |
| Title: | Microsoft Visual Basic Remote Code Execution Vulnerability (978213) |
| Summary: | Check for the version of 'VBE6.DLL' file |
| Description: | Overview: This host is missing a critical security update according to Microsoft Bulletin MS10-031. Vulnerability Insight: The issue is caused by a stack memory corruption error in 'VBE6.DLL' when searching for ActiveX controls in a document that supports VBA. Impact: Successful exploitation will allow remote attackers to crash an affected application or execute arbitrary code by tricking a user into opening a specially crafted document. Impact Level: System/Apllication Affected Software/OS: Microsoft Office XP SP3 and prior. Microsoft Office 2003 SP3 and prior. Microsoft Visual Basic for Applications. 2007 Microsoft Office System SP2 and prior. Microsoft Visual Basic for Applications SDK. Fix: Run Windows Update and update the listed hotfixes or download and update mentioned hotfixes in the advisory from the below link, http://www.microsoft.com/technet/security/bulletin/ms10-031.mspx References: http://support.microsoft.com/kb/976380 http://support.microsoft.com/kb/976382 http://support.microsoft.com/kb/976321 http://support.microsoft.com/kb/974945 http://www.vupen.com/english/advisories/2010/1121 http://www.microsoft.com/technet/security/bulletin/MS10-031.mspx |
| Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2010-0815 Microsoft Security Bulletin: MS10-031 http://www.microsoft.com/technet/security/Bulletin/MS10-031.mspx Cert/CC Advisory: TA10-131A http://www.us-cert.gov/cas/techalerts/TA10-131A.html http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7074 |
| Copyright | Copyright (C) 2010 SecPod |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|