Tuesday, February 6, 2007

Vulnerability in Microsoft Office Could Allow Remote Code Execution

Mais uma falha nos produtos do Office...

Description:
A vulnerability has been reported in Microsoft Office, which can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to an unspecified error when handling strings and can be exploited to cause a memory corruption.

Successful exploitation allows execution of arbitary code.

NOTE: According to Microsoft, the vulnerability is currently being actively exploited via Excel, but other Office applications may also be affected.

Solution:
Do not open untrusted Office documents.

Provided and/or discovered by:
Discovered as a 0-day.

Fonte: Secunia

No comments: