Summary
This host is missing a critical security update according to Microsoft Bulletin MS09-030.
Impact
Successful exploitation could execute arbitrary code on the remote system via a specially crafted Publisher file.
Impact Level: Application
Solution
Run Windows Update and update the listed hotfixes or download and update mentioned hotfixes in the advisory from the below link.
http://www.microsoft.com/technet/security/bulletin/ms09-030.mspx
Insight
The flaw is due to error in calculating object handler data when opening files created in older versions of Publisher. This can be exploited to corrupt memory and cause an invalid value to be dereferenced as a pointer.
Affected
Microsoft Office 2007 SP1 and prior
Microsoft Office Publisher 2007 SP1 and prior
References
Severity
Classification
-
CVE CVE-2009-0566 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Buffer Overrun in the ListBox and in the ComboBox (824141)
- Buffer Overrun In HTML Converter Could Allow Code Execution (823559)
- Cumulative Security Update for Internet Explorer (961260)
- Cumulative Security Update for Internet Explorer (972260)
- Microsoft Wireless LAN AutoConfig Service Remote Code Execution Vulnerability (970710)