Computer Security
[EN] securityvulns.ru no-pyccku


Microsoft Office code execution
Published:10.09.2008
Source:
SecurityVulns ID:9279
Type:client
Threat Level:
5/10
Description:Code execution on OneNote: URI.
Affected:MICROSOFT : Office XP
 MICROSOFT : Office 2003
 MICROSOFT : Office 2007
CVE:CVE-2008-3007 (Argument injection vulnerability in a URI handler in Microsoft Office XP SP3, 2003 SP2 and SP3, 2007 Office System Gold and SP1, and Office OneNote 2007 Gold and SP1 allow remote attackers to execute arbitrary code via a crafted onenote:// URL, aka "Uniform Resource Locator Validation Error Vulnerability.")
Original documentdocumentBrett Moore, Insomnia : ISVA-080910.1 - MS Office OneNote URL Handling Vulnerability (10.09.2008)
 documentMICROSOFT, Microsoft Security Bulletin MS08-055 – Critical Vulnerability in Microsoft Office Could Allow Remote Code Execution (955047) (10.09.2008)
Files:Microsoft Security Bulletin MS08-055 – Critical Vulnerability in Microsoft Office Could Allow Remote Code Execution (955047)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod