| Microsoft Windows Knowledge Base Article 951207 update not installed (WinMs08kb951207Update) |
|---|
| Vuln ID: | 42101 | |
|---|---|---|
| Risk Level: | High |
WinMs08kb951207Update |
| Platforms: | Microsoft Word: 2002 SP3, Microsoft Office Compatibility Pack: 2007, Microsoft Word: 2007, Microsoft Outlook: 2007, Microsoft Word Viewer: 2003, Microsoft Office: 2008 Mac OS, Microsoft Word: 2003 SP2, Microsoft Word: 2000 SP3, Microsoft Office Compatibility Pack: 2007 SP1, Microsoft Outlook: 2007 SP1, Microsoft Office: 2004 Mac OS, Microsoft Word: 2003 SP3, Microsoft Word Viewer: 2003 SP3, Microsoft Word: 2007 SP1 | |
| Description: | Microsoft Windows Knowledge Base Article 951207 update is not installed on the system, which could allow a remote attacker to exploit the following vulnerabilities: Microsoft Word could allow a remote attacker to execute arbitrary code on the system, caused by improper memory calculation when processing a malformed string in a specially-crafted Rich Text Format (.rtf) file. By persuading a victim to open a specially-crafted .rtf file, a remote attacker could exploit this vulnerability to corrupt memory and execute arbitrary code on the system with the privileges of the victim. Microsoft Word could allow a remote attacker to execute arbitrary code on the system, caused by improper memory calculation when processing a malformed CSS value in a specially-crafted Word file. By persuading a victim to open a specially-crafted Word file, a remote attacker could exploit this vulnerability to corrupt memory and execute arbitrary code on the system with the privileges of the victim. |
|
| Remedy: | Apply the appropriate patch for your system, as listed in Microsoft Security Bulletin MS08-026. See References. |
|
| False Positives: | ||
| False Negatives: | ||
| Required Permission: | Windows login | |
| Additional Information: | ||
| References: | Microsoft Security Bulletin MS08-026 IBM Internet Security Systems X-Force Database IBM Internet Security Systems X-Force Database ISS X-Force CVE CVE-2008-1091 |
|
![]() Know Your Risks |
![]() Common Vulnerabilties & Exposures |