First published: Wed Dec 09 2009(Updated: )
Integer overflow in the text converters in Microsoft Office Word 2002 SP3 and 2003 SP3; Works 8.5; Office Converter Pack; and WordPad in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a DOC file with an invalid number of property names in the DocumentSummaryInformation stream, which triggers a heap-based buffer overflow.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 2000 | =sp4 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp3 | |
Microsoft Office Converter Pack | ||
Microsoft Office Word | =2002-sp3 | |
Microsoft Office Word | =2003-sp3 | |
WordPad | ||
Microsoft Works Suite | =8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2506 is rated as a critical vulnerability due to its ability to allow remote code execution.
To fix CVE-2009-2506, users should apply the latest security updates released by Microsoft for the affected software versions.
Microsoft Office Word 2002 SP3, Microsoft Office Word 2003 SP3, and Microsoft Office Converter Pack are affected by CVE-2009-2506.
CVE-2009-2506 impacts Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2.
CVE-2009-2506 can be exploited by attackers through specially crafted DOC files that trigger the integer overflow vulnerability.