TITLE: Microsoft Word 2000 Unspecified Code Execution Vulnerability
SECUNIA ADVISORY ID: SA21735
VERIFY ADVISORY: http://secunia.com/advisories/21735/
CRITICAL: Extremely critical
IMPACT: System access
WHERE: >From remote
SOFTWARE:
Microsoft Word 2000 - http://secunia.com/product/2149/
Microsoft Office 2000 - http://secunia.com/product/24/
DESCRIPTION: A vulnerability has been reported in Microsoft Word 2000, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an unspecified error when processing Word documents. This can be exploited to execute arbitrary code when a malicious document is opened. The vulnerability is reported in Microsoft Word 2000 running on Windows 2000. Other versions may also be affected.
NOTE: The vulnerability is being actively exploited.
SOLUTION: Do not open untrusted Office documents.
PROVIDED AND/OR DISCOVERED BY: Discovered in the wild as a 0-day.
OTHER REFERENCES: Symantec: - http://www.symantec.com/enterprise/security_response/weblog/2006/09/new_tricks_with_old_software.html
Extremely Critical! Microsoft Word 2000 Unspecified Code Execution VulnerabilityPosted on Tuesday, September 05, 2006 @ 07:21:01 CDT in Security |