Intrusion Prevention

MS.Word.RTF.File.Handling.Memory.Corruption

Description

This indicates an attempt to exploit an Integer Overflow vulnerability in Microsoft Word.
The vulnerability is caused by an error that occurs when the vulnerable software handles a malicious "RTF" file. It allows a remote attacker to execute arbitrary code via a crafted "RTF" file.

Affected Products

Microsoft Office 2000 Service Pack 3
Microsoft Office XP Service Pack 3
Microsoft Office 2003 Service Pack 2
Microsoft Office 2003 Service Pack 3
2007 Microsoft Office System
Microsoft Outlook 2007
2007 Microsoft Office System Service Pack 1
Microsoft Outlook 2007 Service Pack 1
Microsoft Word Viewer 2003
Microsoft Word Viewer 2003 Service Pack 3
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Service Pack 1
Microsoft Office 2004 for Mac
Microsoft Office 2008 for Mac

Impact

System compromise: Remote code execution.

Recommended Actions

Apply the patch available from the web site:
http://www.microsoft.com/technet/security/bulletin/ms08-026.mspx

CVE References

CVE-2008-1091