Summary
This host is missing a critical security update according to Microsoft Bulletin MS09-030.
Impact
Successful exploitation could execute arbitrary code on the remote system via a specially crafted Publisher file.
Impact Level: Application
Solution
Run Windows Update and update the listed hotfixes or download and update mentioned hotfixes in the advisory from the below link.
http://www.microsoft.com/technet/security/bulletin/ms09-030.mspx
Insight
The flaw is due to error in calculating object handler data when opening files created in older versions of Publisher. This can be exploited to corrupt memory and cause an invalid value to be dereferenced as a pointer.
Affected
Microsoft Office 2007 SP1 and prior
Microsoft Office Publisher 2007 SP1 and prior
References
Severity
Classification
-
CVE CVE-2009-0566 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Certificate Validation Flaw Could Enable Identity Spoofing (Q328145)
- Microsoft Data Analyzer and IE Developer Tools ActiveX Control Vulnerability (980195)
- Microsoft .NET Framework Multiple Vulnerabilities (2861561)
- Microsoft Group Policy Remote Code Execution Vulnerability (3000483)
- Microsoft IE Developer Tools WMITools and Windows Messenger ActiveX Control Vulnerability (2508272)