Vulnerabilities > CVE-2003-0820 - Unspecified vulnerability in Microsoft Word and Works
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN microsoft
nessus
Summary
Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 27 |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS03-050.NASL |
description | The remote host is running a version of Microsoft Word and/or Microsoft Excel that are subject to a flaw that could allow arbitrary code to be run. An attacker could use this to execute arbitrary code on this host. To succeed, the attacker would have to send a rogue Word or Excel file to the owner of this computer and have him open it. Then the macros contained in the Word file would bypass the security model of Word, and would be executed. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11920 |
published | 2003-11-11 |
reporter | This script is Copyright (C) 2003-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11920 |
title | MS03-050: Word and/or Excel may allow arbitrary code to run (831527) |
code |
|
Oval
accepted 2012-05-28T04:01:39.381-04:00 class vulnerability contributors name Christine Walzer organization The MITRE Corporation name Ingrid Skoog organization The MITRE Corporation name John Hoyland organization Centennial Software name Shane Shaffer organization G2, Inc.
description Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack. family windows id oval:org.mitre.oval:def:336 status accepted submitted 2003-11-19T12:00:00.000-04:00 title MS Word 2000 Macro Names Buffer Overflow version 6 accepted 2016-02-19T10:00:00.000-04:00 class vulnerability contributors name Andrew Buttner organization The MITRE Corporation name Ingrid Skoog organization The MITRE Corporation name Ingrid Skoog organization The MITRE Corporation name Dragos Prisaca organization Secure Elements, Inc. name Shane Shaffer organization G2, Inc.
description Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack. family windows id oval:org.mitre.oval:def:585 status accepted submitted 2003-11-19T12:00:00.000-04:00 title MS Word 97 Macro Names Buffer Overflow version 4 accepted 2016-02-19T10:00:00.000-04:00 class vulnerability contributors name Andrew Buttner organization The MITRE Corporation name Harvey Rubinovitz organization The MITRE Corporation name Shane Shaffer organization G2, Inc.
description Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack. family windows id oval:org.mitre.oval:def:586 status accepted submitted 2003-11-19T12:00:00.000-04:00 title MS Word 98 Macro Names Buffer Overflow version 4 accepted 2012-05-28T04:02:09.735-04:00 class vulnerability contributors name Andrew Buttner organization The MITRE Corporation name Ingrid Skoog organization The MITRE Corporation name John Hoyland organization Centennial Software name Shane Shaffer organization G2, Inc.
description Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack. family windows id oval:org.mitre.oval:def:668 status accepted submitted 2003-11-19T12:00:00.000-04:00 title MS Word 2002 Macro Names Buffer Overflow version 6
References
- http://archives.neohapsis.com/archives/bugtraq/2003-10/0163.html
- http://archives.neohapsis.com/archives/bugtraq/2003-10/0163.html
- http://www.security.nnov.ru/search/document.asp?docid=5243
- http://www.security.nnov.ru/search/document.asp?docid=5243
- http://www.securityfocus.com/bid/8835
- http://www.securityfocus.com/bid/8835
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-050
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-050
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13682
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13682
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A336
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A336
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A585
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A585
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A586
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A586
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A668
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A668