Check Point Reference: | CPAI-2013-3751 |
Date Published: | 22 Dec 2013 |
Severity: | High |
Last Updated: | Tuesday 14 October, 2014 |
Source: | |
Industry Reference: | CVE-2013-3934 |
Protection Provided by: |
Security Gateway |
Who is Vulnerable? | |
Vulnerability Description | A code execution vulnerability has been reported in Kingsoft Writer. The vulnerability is due to an error while handling font names in WPS or Office word files. A remote attacker can exploit this vulnerability by enticing an unsuspecting user to download and process a malicious file with a vulnerable version of the application. This can lead to code execution in the context of the affected user. |
SmartView Tracker will log the following entries:
Attack Name: Content Protection Violation.
Attack Information: Kingsoft Writer Font Names Buffer Overflow