Summary
This host is missing an important security update according to Microsoft Bulletin MS12-076.
Impact
Successful exploitation will allow attackers to execute arbitrary code with the privileges of the user running the affected application.
Impact Level: System/Application
Solution
Run Windows Update and update the listed hotfixes or download and update mentioned hotfixes in the advisory from the below link, http://technet.microsoft.com/en-us/security/bulletin/MS12-076
Insight
- An error when processing the 'SerAuxErrBar' record can be exploited to cause a heap-based buffer overflow via a specially crafted file.
- An input validation error can be exploited to corrupt memory via a specially crafted file.
- A use-after-free error when processing the 'SST' record can be exploited via a specially crafted file.
- An error when processing certain data structures can be exploited to cause a stack-based buffer overflow via a specially crafted file.
Affected
Microsoft Office 2008 for Mac
Microsoft Office 2011 for Mac
References
Severity
Classification
-
CVE CVE-2012-1885, CVE-2012-1886, CVE-2012-1887, CVE-2012-2543 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Microsoft Office Remote Code Execution Vulnerabilities - 2720184 (Mac OS X)
- Microsoft Silverlight Security Bypass Vulnerability (2932677) (Mac OS X)
- Mac OS X 10.5.6 Update / Mac OS X Security Update 2008-008
- Java for Mac OS X 10.6 Update 2
- Apple Mac OS X Predefined Sandbox Profiles Security Bypass Vulnerability