Summary
This host is missing a critical security update according to Microsoft Bulletin MS09-030.
Impact
Successful exploitation could execute arbitrary code on the remote system via a specially crafted Publisher file.
Impact Level: Application
Solution
Run Windows Update and update the listed hotfixes or download and update mentioned hotfixes in the advisory from the below link.
http://www.microsoft.com/technet/security/bulletin/ms09-030.mspx
Insight
The flaw is due to error in calculating object handler data when opening files created in older versions of Publisher. This can be exploited to corrupt memory and cause an invalid value to be dereferenced as a pointer.
Affected
Microsoft Office 2007 SP1 and prior
Microsoft Office Publisher 2007 SP1 and prior
References
Severity
Classification
-
CVE CVE-2009-0566 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Microsoft Hyper-V Privilege Elevation Vulnerability (2893986)
- Microsoft .NET Common Language Runtime Code Execution Vulnerability (974378)
- Microsoft .NET Framework Remote Code Execution Vulnerabilities (2878890)
- Cumulative Security Update for Internet Explorer (956390)
- Microsoft .NET Framework Privilege Elevation Vulnerability (3005210)