Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006 does not properly parse certain rich text "property strings of certain control words," which allows user-assisted remote attackers to trigger heap corruption and execute arbitrary code, aka the "Word RTF Parsing Vulnerability."
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/468871/100/200/threaded | vendor advisory |
http://www.securitytracker.com/id?1018013 | patch vdb entry |
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=525 | third party advisory patch |
http://www.vupen.com/english/advisories/2007/1709 | vdb entry vendor advisory |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-024 | vendor advisory |
http://www.us-cert.gov/cas/techalerts/TA07-128A.html | third party advisory us government resource |
http://www.osvdb.org/34388 | vdb entry |
http://www.kb.cert.org/vuls/id/555489 | third party advisory us government resource |
http://www.securityfocus.com/bid/23836 | patch vdb entry |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1900 | signature vdb entry |