Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:3408
HistoryAug 23, 2002 - 12:00 a.m.

ISS Security Brief: Multiple Vulnerabilities in Microsoft Office Web Components

2002-08-2300:00:00
vulners.com
13

TO UNSUBSCRIBE: email "unsubscribe alert" in the body of your message to
[email protected] Contact [email protected] for help with any problems!

-----BEGIN PGP SIGNED MESSAGE-----

Internet Security Systems Security Alert
August 22, 2002

Multiple Vulnerabilities in Microsoft Office Web Components

Synopsis:

Microsoft has released a security bulletin detailing multiple vulnerabilities
in Office Web Components (OWC). OWC is a component of several Microsoft
products and it provides Microsoft Office functionality within a Web browser.

Impact:

The OWC vulnerabilities can be exploited if a user visits a hostile Web page
or if exploit code is delivered to a recipient via email. This vulnerability
may allow a remote attacker to execute arbitrary commands on vulnerable
systems without having authorized access. This vulnerability and others
like it may be easily integrated into mass-emailing Internet worms.

Affected Versions:

Microsoft Office Web Components 2000
Microsoft Office Web Components 2002
Microsoft BackOffice Server 2000
Microsoft BizTalk Server 2000
Microsoft BizTalk Server 2000
Microsoft Commerce Server 2000
Microsoft Commerce Server 2002
Microsoft Internet Security and Acceleration Server 2000
Microsoft Money 2002
Microsoft Money 2003
Microsoft Office 2000
Microsoft Office XP
Microsoft Project 2002
Microsoft Project Server 2002
Microsoft Small Business Server 2000

For the complete ISS X-Force Security Alert, please visit:
http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21023


About Internet Security Systems (ISS)
Founded in 1994, Internet Security Systems (ISS) (Nasdaq: ISSX) is a
pioneer and world leader in software and services that protect critical
online resources from an ever-changing spectrum of threats and misuse.
Internet Security Systems is headquartered in Atlanta, GA, with
additional operations throughout the Americas, Asia, Australia, Europe
and the Middle East.

Copyright (c) 2002 Internet Security Systems, Inc. All rights reserved
worldwide.

Permission is hereby granted for the electronic redistribution of this
document. It is not to be edited or altered in any way without the
express written consent of the Internet Security Systems X-Force. If you
wish to reprint the whole or any part of this document in any other
medium excluding electronic media, please email [email protected] for
permission.

Disclaimer: The information within this paper may change without notice.
Use of this information constitutes acceptance for use in an AS IS
condition. There are NO warranties, implied or otherwise, with regard to
this information or its use. Any use of this information is at the
user's risk. In no event shall the author/distributor (Internet Security
Systems X-Force) be held liable for any damages whatsoever arising out
of or in connection with the use or spread of this information.

X-Force PGP Key available on MIT's PGP key server and PGP.com's key
server, as well as at http://www.iss.net/security_center/sensitive.php

Please send suggestions, updates, and comments to: X-Force
[email protected] of Internet Security Systems, Inc.

-----BEGIN PGP SIGNATURE-----
Version: 2.6.2

iQCVAwUBPWUfdDRfJiV99eG9AQFuVQP/Yq7GtcKAvhjEloP4pdh4F94jO4yQBV1F
y/ImPSzmaLUS8rdkZKTSIpvEQ83NWzycLwZkCLVw0P+McXCgFQ7rBt88KSIBPg/1
CT/hchAfEBcmQMXLCW6wQD4oFlKB8yh0/7Fz9IS9UVB7yrCh6yiCw2gBlTiXo+9m
KJVMZ+UWtpI=
=88Ne
-----END PGP SIGNATURE-----