Microsoft Office Multiple Vulnerabilities
by Carol~
- 5/8/12 3:49 PM
In Reply to: VULNERABILITIES / FIXES - May 08, 2012 by Carol~
Release Date : 2012-05-08
Criticality level : Highly critical
Impact : System access
Where : From remote
Solution Status : Vendor Patch
Software: Microsoft Office 2003 Professional Edition
Microsoft Office 2003 Small Business Edition
Microsoft Office 2003 Standard Edition
Microsoft Office 2003 Student and Teacher Edition
Microsoft Office 2007
Microsoft Office 2010
Description:
Multiple vulnerabilities have been reported in Microsoft Office, which can be exploited by malicious people to compromise a user's system.
1) Some errors exist when parsing TrueType fonts.
2) An error in the Office GDI+ library when handling EMF images embedded within a document can be exploited to cause a heap-based buffer overflow.
Successful exploitation of the vulnerabilities allows execution of arbitrary code.
Solution:
Apply patches.
Provided and/or discovered by:
2) The vendor credits an anonymous person via iDefense
Original Advisory:
MS12-034 (KB2681578, KB2598253, KB2596672, KB2596792, KB2589337):
http://technet.microsoft.com/en-us/security/bulletin/ms12-034
http://secunia.com/advisories/49121/

Moderator
CNET Staff
Samsung Staff
Dell Staff