| Microsoft Jet Database Engine Word file buffer overflow (MicrosoftJetMsjet40Bo) |
|---|
| Vuln ID: | 41380 | |
|---|---|---|
| Risk Level: | High |
MicrosoftJetMsjet40Bo |
| Platforms: | Microsoft Word: 2007, Microsoft Word: 2003, Microsoft Word: 2000, Microsoft Jet: 4.0 | |
| Description: | Microsoft Jet Database Engine (msjet40.dll) is vulnerable to a stack-based buffer overflow, caused by improper bounds checking when parsing a Word file. By persuading a victim to open a specially-crafted Word file, a remote attacker could cause the victim's application to crash or possibly execute arbitrary code on the victim's system with the privileges of the victim. An attacker could exploit this vulnerability by sending the malicious file as an email attachment or by hosting it on a Web site. An attacker could also exploit this vulnerability by persuading a victim to open a specially-crafted MDB file or an MDB file embedded in a Word document. Refer to SecChkID 38499. See References. |
|
| Remedy: | Apply the appropriate patch for your system, as listed in Microsoft Security Bulletin MS08-028. See References. |
|
| False Positives: | ||
| False Negatives: | ||
| Required Permission: | Windows login | |
| Additional Information: | ||
| References: | Microsoft Security Advisory (950627) Microsoft Security Bulletin MS08-028 IBM Internet Security Systems X-Force Database HPSBST02336 SSRT080071 rev.1 ISS X-Force CVE CVE-2008-1092 |
|
![]() Know Your Risks |
![]() Common Vulnerabilties & Exposures |