A
vulnerability has been identified in Microsoft Windows, which could be
exploited by attackers to take complete control of an affected system.
This issue is due to a memory corruption error in certain MFC
components when parsing OLE objects embedded within RTF files, which
could be exploited by remote attackers to execute arbitrary commands by
convincing a user to interact with a malformed embedded OLE object
within a Rich Text Format (RTF) file.
Affected Products
Microsoft Windows 2000 Service Pack 4
Microsoft Windows XP Service Pack 2
Microsoft Windows XP Professional x64 Edition
Microsoft Windows Server 2003
Microsoft Windows Server 2003 Service Pack 1
Microsoft Windows Server 2003 (Itanium)
Microsoft Windows Server 2003 SP1 (Itanium)
Microsoft Windows Server 2003 x64 Edition
Microsoft Visual Studio .NET 2002
Microsoft Visual Studio .NET 2002 Service Pack 1
Microsoft Visual Studio .NET 2003
Microsoft Visual Studio .NET 2003 Service Pack 1
Solution
Update for Microsoft Windows 2000 Service Pack 4 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=d6577f1f-0d9e-4856-b1d6-7e27657a3620
Update for Microsoft Windows XP Service Pack 2 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=84ae4c62-89ae-410a-b34b-471e3c09ce98
Update for Microsoft Windows XP Professional x64 Edition :
http://www.microsoft.com/downloads/details.aspx?FamilyId=54e0dc33-6bad-476c-b4cf-b833d591aaad
Update for Microsoft Windows Server 2003 and Windows Server 2003 Service Pack 1 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=934ca609-d6bc-4bf0-8233-969eb43d48bb
Update for Microsoft Windows Server 2003 (Itanium) and Windows Server 2003 SP1 (Itanium) :
http://www.microsoft.com/downloads/details.aspx?FamilyId=67f52e93-cd57-4852-b838-a958ab9b23fb
Update for Microsoft Windows Server 2003 x64 Edition :
http://www.microsoft.com/downloads/details.aspx?FamilyId=f2ca9de9-f69e-4e34-9aa9-0b320d670e04
Update for Microsoft Visual Studio .NET 2002 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=711F05A8-CD67-4702-B079-3FF79A3AB4DE
Update for Microsoft Visual Studio .NET 2002 Service Pack 1 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=124F2D2D-8CF3-47F3-A8FD-24A9FACF4FA4
Update for Microsoft Visual Studio .NET 2003 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=A05CE727-C5B5-4022-B7A0-D8861CE99209
Update for Microsoft Visual Studio .NET 2003 Service Pack 1 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=1DD6D8E7-390B-4E02-9F16-AB9D5EF7792E