Microsoft Office Object Library "LsCreateLine()" Improper Memory Access Vulnerability
Technical Description



A vulnerability has been identified in Microsoft Office, which could beexploited by attackers to cause a denial of service or potentially takecomplete control of an affected system. This flaw is due to a memoryaccess error in the "mso.dll" library when handling a malformeddocument, which could be exploited by attackers to crash a vulnerableapplication or execute arbitrary commands by convincing a user to opena specially crafted Word document.



Note : A proof of concept exploit has been released.



Affected Products



Microsoft Office 2000

Microsoft Office XP

Microsoft Office 2003

Microsoft Word 2000

Microsoft Word 2002

Microsoft Word 2003
더보기

댓글,