First published: Tue Feb 13 2007(Updated: )
The MFC component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 and Visual Studio .NET 2000, 2002 SP1, 2003, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption. NOTE: this might be due to a stack-based buffer overflow in the AfxOleSetEditMenu function in MFC42u.dll.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Visual Studio .NET | =2003-gold | |
Microsoft Visual Studio .NET | =2000-sp1 | |
Microsoft Visual Studio .NET | =2000 | |
Microsoft Windows 2003 Server | =2003-sp2 | |
Microsoft Windows 2003 Server | =xp_sp2 | |
Microsoft Windows 2003 Server | =2000-sp4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.