VID |
26360 |
Severity |
40 |
Port |
139,445 |
Protocol |
TCP |
Class |
SMB |
Detailed Description |
The hotfix (MS08-044, 924090) for 'Remote Code Execution Vulnerabilities in Microsoft Office Filters' has not been applied. Microsoft Office 2000, 2002, and 2003, and Microsoft Project 2002 could allow a remote attacker to execute arbitrary code, caused by multiple buffer overflow vulnerabilities that exist in the Microsoft Office filters. By creating a specially-crafted PICT-format image file, BMP-format image file, WPG-format image file, or EPS file, a remote attacker could overflow a buffer and execute arbitrary code on the system, once the file is open. An attacker could exploit these vulnerabilities by hosting the malicious file on a Web site and then persuading a potential victim to visit the site or sending the file to a potential victim as an email attachment.
* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of these condition will result in the check not being performed and a False Negative for all vulnerable hosts.
* References: http://www.microsoft.com/technet/security/bulletin/ms08-044.mspx
* Platforms Affected: Microsoft Office 2000 SP3 Microsoft Office XP SP3 Microsoft Office 2003 SP2 Microsoft Office Converter Pack Microsoft Project 2002 SP1 Microsoft Works 8.0 Microsoft Windows Any version |
Recommendation |
Apply the appropriate patch (924090) for your system, as listed in Microsoft Security Bulletin MS08-044 at http://www.microsoft.com/technet/security/bulletin/ms08-044.mspx |
Related URL |
CVE-2008-0113,CVE-2008-0118 (CVE) |
Related URL |
23826,28146 (SecurityFocus) |
Related URL |
40887,40888,40889 (ISS) |
|