VID |
26522 |
Severity |
40 |
Port |
139,445 |
Protocol |
TCP |
Class |
SMB |
Detailed Description |
The Hotfix (MS10-056, 2269638) for 'Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution' has not been applied. This security update resolves four privately reported vulnerabilities in Microsoft Office. The most severe vulnerabilities could allow remote code execution if a user opens or previews a specially crafted RTF e-mail message. The update addresses the vulnerabilities by modifying the way that Microsoft Office Word opens specially crafted Word files and by modifying the way that Word handles certain properties of rich text data.
* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of these condition will result in the check not being performed and a False Negative for all vulnerable hosts.
* References: http://www.microsoft.com/technet/security/Bulletin/MS10-056.mspx
* Platforms Affected: Microsoft Office XP Service Pack 3 Microsoft Office 2003 Service Pack 3 2007 Microsoft Office System Service Pack 2 Microsoft Office 2004 for Mac Microsoft Office 2008 for Mac Open XML File Format Converter for Mac Microsoft Office Word Viewer Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Service Pack 2 Microsoft Works 9 |
Recommendation |
Apply the appropriate patch (2269638) for your system, as listed in Microsoft Security Bulletin MS10-056 at http://www.microsoft.com/technet/security/bulletin/ms10-056.mspx |
Related URL |
CVE-2009-3135 (CVE) |
Related URL |
36950 (SecurityFocus) |
Related URL |
(ISS) |
|