1. Symantec/
  2. Security Response/
  3. Attack Signatures/
  4. Web Attack: MS Office Word RTF RCE 1

Web Attack: MS Office Word RTF RCE 1

Severity: High

This attack could pose a serious security threat. You should take immediate action to stop any damage or prevent further damage from happening.

Description

This signature will detect attempts to exploit a remote code execution vulnerability in MS Word.

Additional Information

Microsoft Office is prone to a remote stack-based buffer-overflow vulnerability because the software fails to perform adequate boundary-checks on user-supplied data. This issue occurs when the application parses property strings from specially crafted RTF data.

An attacker can exploit this issue by enticing an unsuspecting user to open a malicious RTF file or view an email in RTF format.

Successfully exploiting this issue would allow the attacker to corrupt memory and execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will result in a denial-of-service condition.

Affected

  • Microsoft Office

Response

The vendor has released an advisory and updates. Please see the references for more information.
  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube