邪恶八进制信息安全团队技术讨论组's Archiver

pub!1c 2007-2-4 11:46

Microsoft Word 2000 Unspecified Code Execution Exploit (0day)

[code]
+ Title: Microsoft Word 2000 Unspecified Code Execution Vulnerability Exploit (0-day)

+ code by xCuter (BongGoo Kang - [email]xcuter@returnaddr.org[/email])
        
+ Critical: High Critical

+ Impact: MS Word 2000 -> Could Allow Arbitrary Command Execution
       MS word 2003 -> Attempts against Word 2003/XP will consume all CPU resources and will cause a denial of service

+ Where: From remote

+ Tested Operating System: Windows XP SP2 FULL PATCHED (Korean Language)

+ Tested Software: Microsoft(R) Word 2000 (9.0.2720)

+ Solution: Not Patched (zero-day)

+ Description:
  When a user opens a specially crafted Word file using a malformed string,
  it may corrupt system memory in such a way that an attacker could execute arbitrary code
  This exploit will be execute command - 'CMD.EXE'

+ Reference : [url]http://www.microsoft.com/technet/security/advisory/932114.mspx[/url] - Microsoft Security Advisory (932114)


[/code]

页: [1]
© 1999-2008 EvilOctal Security Team