Check Point Reference: | SBP-2008-01 |
Date Published: | 12 Feb 2008 |
Severity: | Critical |
Last Updated: | Tuesday 01 January, 2008 |
Source: | Microsoft Security Bulletin MS08-012 |
Industry Reference: | CVE-2008-0102 CVE-2008-0104 |
Protection Provided by: | |
Who is Vulnerable? | Microsoft Publisher 2000 SP3 Microsoft Publisher 2002 SP3 Microsoft Publisher 2003 SP2 |
Vulnerability Description | Multiple vulnerabilities have been reported in Microsoft Publisher. Microsoft Publisher is a desktop publishing application for creating marketing materials, managing customer lists and more. A remote attacker can exploit these vulnerabilities via a specially crafted .pub file. Successful exploitation may allow execution of arbitrary code on a vulnerable system. |
Update/Patch Avaliable | Apply patches: Microsoft Security Bulletin MS08-012 |
Vulnerability Details | The vulnerabilities are due to a memory corruption error in Microsoft Publisher that fails to properly handle malformed files. A remote attacker could trigger these flaws by convincing the victim to open a specially crafted Publisher file (.pub). Successful exploitation of these issues may allow execution of arbitrary code once the malformed file is opened on a vulnerable system. |