(MS04-027) Vulnerability in WordPerfect Converter Could Allow Code Executi

Vulnerability Identifier: CAN-2004-0573
Risk: Important
Discovery Date: 09.14.2004
Vulnerability Assessment Pattern File: 016

Affected Software:
  • Microsoft FrontPage 2000
  • Microsoft FrontPage 2002
  • Microsoft FrontPage 2003
  • Microsoft Office 2000
  • Microsoft Office 2003
  • Microsoft Office XP
  • Microsoft Publisher 2000
  • Microsoft Publisher 2002
  • Microsoft Publisher 2003
  • Microsoft Word 2000
  • Microsoft Word 2002
  • Microsoft Word 2003
  • Microsoft Works Suite 2001
  • Microsoft Works Suite 2002
  • Microsoft Works Suite 2003
  • Microsoft Works Suite 2004

Description:

This remote code execution vulnerability could allow a malicious user or a malware to take complete control of the affected system if the affected user is currently logged on with administrative privileges. The malicious user or malware can execute code on the system giving them the ability to install or run programs and view or edit data with full privileges. Thus, this vulnerability can conceivably be used by a malware for replication purposes.

The vulnerability is caused by an unchecked buffer in the Microsoft Office WordPerfect Converter.

The Microsoft Office WordPerfect converter helps users convert documents from Corel WordPerfect file formats to Microsoft Word file formats. The WordPerfect converter is included in all versions of Office and is also available separately in the Microsoft Office Converter Pack.

This vulnerability can be exploited by a remote malicious attacker or a malware by:

  • Web-based attack scenario:

    An attacker would have to host a Web site that contains a Web page that is used to exploit this vulnerability. An attacker would have no way to force users to visit a malicious Web site. Instead, an attacker would have to persuade them to visit the Web site, typically by getting them to click a link that takes them to the attacker's site. After they click the link, they would be prompted to perform several actions. An attack could only occur after they performed these actions.

  • E-mail attack scenario:

    A user must open an attachment that is sent in an e-mail message for an attack to be successful through e-mail.

A malware or an attacker who successfully exploits this vulnerability could gain the same privileges as the user. Users whose accounts are configured to have fewer privileges on the system would be at less risk than users who operate with administrative privileges.

Note that this update replaces the security update that was provided as part of Microsoft Security Bulletin MS03-036.

Patch Information

Workaround:

  • Do not open WordPerfect documents using the affected WordPerfect Converter.

    Do not open WordPerfect documents from untrusted sources, using any of the software enumerated as affected in this bulletin, on systems that are not updated with the security updates accompanying this security bulletin.

  • Use a third party WordPerfect to Word converter or ask the user of WordPerfect to save the document in another format.

Comments

Posted by   www
on June 21, 2010, 8:45 pm
http://astore.amazon.com/3m.headlight.restoration.kit-20
http://astore.amazon.com/abu.garcia.baitcasting.reels-20
http://astore.amazon.com/akebono.brake.pad.set-20
http://astore.amazon.com/anco.wiper-blades-20
http://astore.amazon.com/auto.battery.maintainer-20
http://astore.amazon.com/battery.tender.plus-20
http://astore.amazon.com/behringer.guitar.amplifier-20
http://astore.amazon.com/bicycle.bottle.cage.sale-20
http://astore.amazon.com/bicycle.water.bottle.cage-20
http://astore.amazon.com/bike.floor.pump.sale-20
http://astore.amazon.com/bosch-wiper.blades-20
http://astore.amazon.com/bosch.icon.wiper.blades-20
http://astore.amazon.com/bosch.iridium.spark.plugs-20
http://astore.amazon.com/boss.amplifier.4.channel-20
http://astore.amazon.com/boss.executive.chairs-20
http://astore.amazon.com/boss.leather.chair-20
http://astore.amazon.com/buy.cheap.dining.room.furniture.online-20
http://astore.amazon.com/buy.monroe.brake.pad-20
http://astore.amazon.com/buy.pennzoil.motor.oil-20
http://astore.amazon.com/carbon.kevlar.motorcycle.gloves-20
http://astore.amazon.com/castrol.motor.oil.sale-20
http://astore.amazon.com/cateye.bike.computer.sale-20
http://astore.amazon.com/cheap.down.alternative.comforter.twin-20
http://astore.amazon.com/cheap.motorcycle.saddlebags-20
http://astore.amazon.com/cheap.usb.condenser.microphone-20
http://astore.amazon.com/cheap.wireless.headset.microphones-20
http://astore.amazon.com/chromatic.harmonica.key.c-20
http://astore.amazon.com/comforter.alternative.down-20
http://astore.amazon.com/crayola.color.explosion.glow.board-20
http://astore.amazon.com/cutlery.sets.for.sale-20
http://astore.amazon.com/daiwa.baitcasting.reels-20
http://astore.amazon.com/deluxe.leather.executive.office.chair-20
http://astore.amazon.com/denso.iridium.spark.plugs-20
http://astore.amazon.com/diamondback.mountain.bikes.sale-20
http://astore.amazon.com/dip.wheel-20
http://astore.amazon.com/down.alternative.comforter.king-20
http://astore.amazon.com/down.alternative.comforter.queen-20
http://astore.amazon.com/dunlop.tortex.guitar.picks-20
http://astore.amazon.com/ebc.brakes.pads-20
http://astore.amazon.com/etq.portable.generator-20
http://astore.amazon.com/executive.desk.chair.leather-20
http://astore.amazon.com/fox.racing.hc.jersey-20
http://astore.amazon.com/generac.portable.generator-20
http://astore.amazon.com/handheld.infrared.thermometer-20
http://astore.amazon.com/harley.davidson.half.helmet-20
http://astore.amazon.com/harley.davidson.oil.filters-20
http://astore.amazon.com/hawk.brake.pad.set-20
http://astore.amazon.com/hercules.dj.console.rmx-20
http://astore.amazon.com/hohner.marine.band.harmonica-20
http://astore.amazon.com/infrared.thermometer.cooking-20
http://astore.amazon.com/joe.rocket.rasp.jacket-20
http://astore.amazon.com/jump.starter.with.air.compressor-20
http://astore.amazon.com/k.n.motorcycle.air.filter-20
http://astore.amazon.com/leather.motorcycle.saddlebags-20
http://astore.amazon.com/ludwig.drum.set.for.sale-20
http://astore.amazon.com/marshall.guitar.amps.for.sale-20
http://astore.amazon.com/medical.infrared.thermometer-20
http://astore.amazon.com/microfiber.cleaning.cloth.glasses-20
http://astore.amazon.com/mongoose-mountain-bikes-sale-20
http://astore.amazon.com/mongoose.bmx.bicycles-20
http://astore.amazon.com/motegi.racing.wheels-20
http://astore.amazon.com/motorcycle.half.helmets-20
http://astore.amazon.com/motorcycle.sissy.bar.bag-20
http://astore.amazon.com/olympia.motorcycle.gloves-20
http://astore.amazon.com/oxo-good-grips-20
http://astore.amazon.com/pearl.drum.sets.for.sale-20
http://astore.amazon.com/phosphor.bronze.acoustic.guitar.strings-20
http://astore.amazon.com/planet-bike-fenders-20
http://astore.amazon.com/planet.bike.blaze-20
http://astore.amazon.com/planet.bike.light.sale-20
http://astore.amazon.com/planet.bike.pump.sale-20
http://astore.amazon.com/platinum.wheels-20
http://astore.amazon.com/portable.jump.starter-20
http://astore.amazon.com/power.trip.vtx.mesh.jacket-20
http://astore.amazon.com/primaloft.comforter.sale-20
http://astore.amazon.com/quantum.baitcasting.reels-20
http://astore.amazon.com/rain-x.wiper.blade-20
http://astore.amazon.com/rogue.guitar.acoustic-20
http://astore.amazon.com/royal.purple.synthetic.motor.oil-20
http://astore.amazon.com/schwinn.mountain.bike.sale-20
http://astore.amazon.com/sennheiser.dynamic.microphones-20
http://astore.amazon.com/shimano.baitcasting.reels-20
http://astore.amazon.com/shimano.spinning.reels-20
http://astore.amazon.com/sigma.wireless.bike.computer-20
http://astore.amazon.com/teknic.motorcycle.glove-20
http://astore.amazon.com/thule.bike.rack.sale-20
http://astore.amazon.com/thule.cargo.bag-20
http://astore.amazon.com/thule.cargo.box-20
http://astore.amazon.com/toy.story.dvd.for.sale-20
http://astore.amazon.com/trico.wiper.blades-20
http://astore.amazon.com/valeo.wiper-blades-20
http://astore.amazon.com/valvoline-motor-oil-sale-20
http://astore.amazon.com/veloche.wheels-20
http://astore.amazon.com/warn.atv.winches.for.sale-20
http://astore.amazon.com/water.dispenser.hot.and.cold-20
http://astore.amazon.com/xlr.male.to.xlr.female.microphone.cable-20
http://astore.amazon.com/yakima.cargo.box.sale-20
http://astore.amazon.com/yamaha.drum.set.for.sale-20
http://astore.amazon.com/zwipes.microfiber.cleaning.cloth-20


 
Name

Email

URL


Remember me?

Comments


Verification code
Verification code