Korean
<< Back
VID 26337
Severity 40
Port 139,445
Protocol TCP
Class SMB
Detailed Description The hotfix (MS08-019, 949032) for 'Remote Code Execution Vulnerabilities in Microsoft Visio' has not been applied. Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 could allow a remote attacker to execute arbitrary code on the system, caused by improper validation of object header data and memory resource allocation when opening Visio files. By constructing a specially crafted Web page containing a malicious Visio file, a remote attacker could potentially execute arbitrary code if a user visited a Web site or viewed a specially crafted e-mail message. An attacker who successfully exploited these vulnerabilities could take complete control of an affected system.

* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of these condition will result in the check not being performed and a False Negative for all vulnerable hosts.

* References:
http://www.microsoft.com/technet/security/bulletin/ms08-019.mspx
http://secunia.com/advisories/29691
http://www.frsirt.com/english/advisories/2008/1143

* Platforms Affected:
Microsoft Visio 2002 SP2
Microsoft Visio 2003 SP2
Microsoft Visio 2003 SP3
Microsoft Visio 2007 SP1
Microsoft Visio 2007
Microsoft Windows Any version
Recommendation Apply the appropriate patch (949032) for your system, as listed in Microsoft Security Bulletin MS08-019 at http://www.microsoft.com/technet/security/bulletin/ms08-019.mspx

-- OR --

Patches for Windows platforms are also available from the Microsoft Windows Update Web site, http://windowsupdate.microsoft.com . Windows Update detects what version of Windows you are running and offers the appropriate patch.
Related URL CVE-2008-1089,CVE-2008-1090 (CVE)
Related URL 28555,28556 (SecurityFocus)
Related URL 41451,41452,41453 (ISS)