Vulnerabilities > CVE-2009-2506 - Numeric Errors vulnerability in Microsoft products
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
Integer overflow in the text converters in Microsoft Office Word 2002 SP3 and 2003 SP3; Works 8.5; Office Converter Pack; and WordPad in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a DOC file with an invalid number of property names in the DocumentSummaryInformation stream, which triggers a heap-based buffer overflow.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 5 | |
Application | 5 |
Common Weakness Enumeration (CWE)
Msbulletin
bulletin_id | MS09-073 |
bulletin_url | |
date | 2009-12-08T00:00:00 |
impact | Remote Code Execution |
knowledgebase_id | 975539 |
knowledgebase_url | |
severity | Important |
title | Vulnerability in WordPad and Office Text Converters Could Allow Remote Code Execution |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS09-073.NASL |
description | The remote host contains a vulnerable version of Microsoft WordPad, Office, or Office Converter Pack. Opening a specially crafted Word 97 file can result in the execution of arbitrary code. A remote attacker could exploit this by tricking a user into opening a malicious Word file. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 43065 |
published | 2009-12-08 |
reporter | This script is Copyright (C) 2009-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/43065 |
title | MS09-073: Vulnerability in WordPad and Office Text Converters Could Allow Remote Code Execution (975539) |
code |
|
Oval
accepted | 2015-08-10T04:00:59.443-04:00 | ||||||||||||||||||||||||||||||||||||||||||||||||||||
class | vulnerability | ||||||||||||||||||||||||||||||||||||||||||||||||||||
contributors |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||
definition_extensions |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||
description | Integer overflow in the text converters in Microsoft Office Word 2002 SP3 and 2003 SP3; Works 8.5; Office Converter Pack; and WordPad in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a DOC file with an invalid number of property names in the DocumentSummaryInformation stream, which triggers a heap-based buffer overflow. | ||||||||||||||||||||||||||||||||||||||||||||||||||||
family | windows | ||||||||||||||||||||||||||||||||||||||||||||||||||||
id | oval:org.mitre.oval:def:5846 | ||||||||||||||||||||||||||||||||||||||||||||||||||||
status | accepted | ||||||||||||||||||||||||||||||||||||||||||||||||||||
submitted | 2009-12-08T13:00:00 | ||||||||||||||||||||||||||||||||||||||||||||||||||||
title | WordPad and Office Text converter Memory Corruption Vulnerability | ||||||||||||||||||||||||||||||||||||||||||||||||||||
version | 30 |
Seebug
bulletinFamily | exploit |
description | BUGTRAQ ID: 37216 CVE ID: CVE-2009-2506 写字板是Windows操作系统中附件所提供的简单文本编辑工具。 当用户打开特制的Word 97文件时,Microsoft写字板和Word文本转换器中的内存破坏漏洞可能导致执行任意代码。在解析DOC文件中的 DocumentSummaryInformation流时会触发这个漏洞。这个流用于提供有关文档作者、创建日期等信息,其中的部分数据是属性名称和数值对序列。在读取这些属性的名称时,代码使用代表名称数目的文件中的32位整数执行了计算。由于没有对所使用的值执行边界检查,这可能触发整数溢出,导致对存储属性数据分配了不充分的堆缓冲区。 Microsoft Windows XP SP3 Microsoft Windows XP SP2 Microsoft Windows Server 2003 SP2 Microsoft Windows 2000SP4 Microsoft Word 2003 SP3 Microsoft Word 2002 SP3 Microsoft Works 8.5 临时解决方法: * 通过限制对转换器文件的访问禁用Word 97的写字板文本转换器,从管理员命令提示符运行以下命令: echo y| cacls "%ProgramFiles%\Common Files\Microsoft Shared\TextConv\mswrd832.cnv" /E /P everyone:N echo y| cacls "%ProgramFiles(x86)%\Common Files\Microsoft Shared\TextConv\mswrd832.cnv" /E /P everyone:N echo y| cacls "%ProgramFiles%\Windows NT\Accessories\mswrd8.wpc" /E /P everyone:N echo y| cacls "%ProgramFiles%\Windows NT\Accessories\mswrd864.wpc" /E /P everyone:N echo y| cacls "%ProgramFiles(x86)%\Windows NT\Accessories\mswrd8.wpc" /E /P everyone:N 厂商补丁: Microsoft --------- Microsoft已经为此发布了一个安全公告(MS09-073)以及相应补丁: MS09-073:Vulnerability in WordPad and Office Text Converters Could Allow Remote Code Execution (975539) 链接:http://www.microsoft.com/technet/security/bulletin/MS09-073.mspx?pf=true |
id | SSV:15051 |
last seen | 2017-11-19 |
modified | 2009-12-12 |
published | 2009-12-12 |
reporter | Root |
title | Microsoft写字板和Office文本转换器Word 97文件解析远程代码执行漏洞(MS09-073) |
References
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=834
- http://support.avaya.com/css/P8/documents/100070184
- http://www.securityfocus.com/bid/37216
- http://www.us-cert.gov/cas/techalerts/TA09-342A.html
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-073
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5846