Summary
This host is missing a critical security update according to Microsoft Bulletin MS12-079.
Impact
Successful exploitation could allow attackers to execute arbitrary code by tricking a user into opening a specially crafted word and RTF files.
Impact Level: System/Application
Solution
Run Windows Update and update the listed hotfixes or download and update mentioned hotfixes in the advisory from the below link, http://technet.microsoft.com/en-us/security/bulletin/ms12-079
Insight
The flaw is due to an error when parsing Rich Text Format (RTF) data related to the listoverridecount and can be exploited to corrupt memory.
Affected
Microsoft Word Viewer
Microsoft Office 2003 Service Pack 3
Microsoft Office 2007 Service Pack 2
Microsoft Office 2007 Service Pack 3
Microsoft Office 2010 Service Pack 1
Microsoft Office Web Apps 2010 Service Pack 1
Microsoft SharePoint Server 2010 Service Pack 1
Microsoft Office Compatibility Pack Service Pack 2 Microsoft Office Compatibility Pack Service Pack 3
References
- http://secunia.com/advisories/51467/
- http://support.microsoft.com/kb/2687412
- http://support.microsoft.com/kb/2760405
- http://support.microsoft.com/kb/2760410
- http://support.microsoft.com/kb/2760416
- http://support.microsoft.com/kb/2760421
- http://support.microsoft.com/kb/2760497
- http://support.microsoft.com/kb/2760498
- http://technet.microsoft.com/en-us/security/bulletin/ms12-079
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2012-2539 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Cumulative Security Update for Internet Explorer (939653)
- Microsoft IIS FTP Service Remote Code Execution Vulnerabilities (975254)
- Microsoft Internet Explorer HTML Rendering Remote Memory Corruption Vulnerability (944533)
- Microsoft Excel Could Allow Remote Code Execution Vulnerabilities (954066)
- Microsoft Ancillary Function Driver Elevation of Privilege Vulnerability (956803)