Lucene search

K
zdiArnaud Dovi 'class101' http://heapoverflow.comZDI-06-034
HistoryOct 10, 2006 - 12:00 a.m.

Microsoft Word Malformed Chart Code Execution Vulnerability

2006-10-1000:00:00
Arnaud Dovi 'class101' http://heapoverflow.com
www.zerodayinitiative.com
13

0.841 High

EPSS

Percentile

98.5%

This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Microsoft Office. Exploitation requires that the attacker coerce the target user into opening a malicious .XLS file. The specific flaw exists during the processing of malformed charts embedded within a Word document. Upon closing the document, certain pointers are corrupted with data direclty from the file. A later dereference of these corrupted pointers can result in code execution.

0.841 High

EPSS

Percentile

98.5%