| CVE-2008-0118 |
|
发布时间 :2008-03-11 19:44:00 | ||
| 修订时间 :2011-03-07 22:03:58 | ||||
| NMCOS |
[原文]Unspecified vulnerability in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, Excel Viewer 2003 up to SP3, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption from an “allocation error,” aka “Microsoft Office Memory Corruption Vulnerability.”
[CNNVD]Microsoft Office单元格标注解析内存破坏漏洞(MS08-014)(CNNVD-200803-173)
Microsoft Office是非常流行的办公软件套件。
Office处理特制Office文件的方式存在内存分配错误,如果用户受骗打开了畸形文件的话,就可能导致执行任意指令。
–
CVSS (基础分值)
| CVSS分值: | 9.3 | [严重(HIGH)] |
| 机密性影响: | COMPLETE | [完全的信息泄露导致所有系统文件暴露] |
| 完整性影响: | COMPLETE | [系统完整性可被完全破坏] |
| 可用性影响: | COMPLETE | [可能导致系统完全宕机] |
| 攻击复杂度: | MEDIUM | [漏洞利用存在一定的访问条件] |
| 攻击向量: | NETWORK | [攻击者不需要获取内网访问权或本地访问权] |
| 身份认证: | NONE | [漏洞利用无需身份认证] |
–
CWE (弱点类目)
| CWE-94 | [对生成代码的控制不恰当(代码注入)] |
–
CPE (受影响的平台与产品)
| cpe:/a:microsoft:office:xp:sp3 | Microsoft Office XP Service Pack 3 |
| cpe:/a:microsoft:office:2000:sp3 | Microsoft Office 2000 sp3 |
| cpe:/a:microsoft:office:2003:sp2 | Microsoft Office 2003 sp2 |
| cpe:/a:microsoft:office:2004::mac | Microsoft Office 2004 Mac |
–
OVAL (用于检测的技术细节)
| oval:org.mitre.oval:def:5190 | Microsoft Office Memory Corruption Vulnerability |
| *OVAL详细的描述了检测该漏洞的方法,你可以从相关的OVAL定义中找到更多检测该漏洞的技术细节。 | |
–
官方数据库链接
–
其它链接及资源
|
http://www.us-cert.gov/cas/techalerts/TA08-071A.html (PATCH) CERT TA08-071A |
|
http://www.securityfocus.com/bid/28146 (PATCH) BID 28146 |
|
http://www.microsoft.com/technet/security/bulletin/ms08-016.mspx (PATCH) MS MS08-016 |
|
http://www.vupen.com/english/advisories/2008/0848/references (UNKNOWN) VUPEN ADV-2008-0848 |
|
http://www.securitytracker.com/id?1019578 (UNKNOWN) SECTRACK 1019578 |
|
http://secunia.com/advisories/29321 (VENDOR_ADVISORY) SECUNIA 29321 |
|
http://marc.info/?l=bugtraq&m=120585858807305&w=2 (UNKNOWN) HP HPSBST02320 |
|
http://marc.info/?l=bugtraq&m=120585858807305&w=2 (UNKNOWN) HP HPSBST02320 |
–
漏洞信息
| Microsoft Office单元格标注解析内存破坏漏洞(MS08-014) | |
| 高危 | 代码注入 |
| 2008-03-11 00:00:00 | 2008-09-05 00:00:00 |
| 远程 | |
| Microsoft Office是非常流行的办公软件套件。 Office处理特制Office文件的方式存在内存分配错误,如果用户受骗打开了畸形文件的话,就可能导致执行任意指令。 |
|
–
公告与补丁
|
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接: http://www.microsoft.com/technet/security/Bulletin/MS08-016.mspx?pf=true |
–
漏洞信息
42709 |
|
| Microsoft Office Unspecified Malformed Document Handling Memory Corruption | |
Local Access Required, Remote / Network Access, Context Dependent |
Input Manipulation |
| Loss of Integrity | Patch / RCS |
| Exploit Commercial | Vendor Verified |
–
漏洞描述
| An unspecified memory corruption flaw exists in Office. With a specially crafted Office file, an attacker can cause arbitrary code execution resulting in a loss of integrity. |
–
时间线
2008-03-11 |
Unknow |
| Unknow | 2008-03-11 |
–
解决方案
| Currently, there are no known workarounds or upgrades to correct this issue. However, Microsoft has released a patch to address this vulnerability. |
–
相关参考
|
–
漏洞作者
| Unknown or Incomplete |
–
漏洞信息
| Microsoft Office File Memory Corruption Vulnerability | |
Boundary Condition Error |
28146 |
| Yes | No |
| 2008-03-11 12:00:00 | 2008-04-18 12:27:00 |
The vendor credits an anonymous source with reporting this issue. |
|
–
受影响的程序版本
| Microsoft Office XP SP3
+ Microsoft Excel 2002 SP3
+ Microsoft Excel 2002 SP3
+ Microsoft FrontPage 2002 SP3
+ Microsoft FrontPage 2002 SP3
+ Microsoft Outlook 2002 SP3
+ Microsoft Outlook 2002 SP3
+ Microsoft PowerPoint 2002 SP3
+ Microsoft PowerPoint 2002 SP3
+ Microsoft Publisher 2002 SP3
+ Microsoft Publisher 2002 SP3 Microsoft Office XP SP2
– Microsoft Windows 2000 Professional SP3
– Microsoft Windows 2000 Professional SP2
– Microsoft Windows 2000 Professional SP1
– Microsoft Windows 2000 Professional
– Microsoft Windows 98
– Microsoft Windows 98SE
– Microsoft Windows ME
– Microsoft Windows NT Workstation 4.0 SP6a
– Microsoft Windows NT Workstation 4.0 SP6
– Microsoft Windows NT Workstation 4.0 SP5
– Microsoft Windows NT Workstation 4.0 SP4
– Microsoft Windows NT Workstation 4.0 SP3
– Microsoft Windows NT Workstation 4.0 SP2
– Microsoft Windows NT Workstation 4.0 SP1
– Microsoft Windows NT Workstation 4.0
– Microsoft Windows XP Home SP1
– Microsoft Windows XP Home
– Microsoft Windows XP Professional SP1
– Microsoft Windows XP Professional Microsoft Office XP SP1
– Microsoft Windows 2000 Professional SP2
– Microsoft Windows 2000 Professional SP1
– Microsoft Windows 2000 Professional
– Microsoft Windows 98
– Microsoft Windows ME
– Microsoft Windows NT Workstation 4.0 SP6a
– Microsoft Windows NT Workstation 4.0 SP6
– Microsoft Windows NT Workstation 4.0 SP5
– Microsoft Windows NT Workstation 4.0 SP4
– Microsoft Windows NT Workstation 4.0 SP3
– Microsoft Windows NT Workstation 4.0 SP2
– Microsoft Windows NT Workstation 4.0 SP1
– Microsoft Windows NT Workstation 4.0
– Microsoft Windows XP Home
– Microsoft Windows XP Professional Microsoft Office XP
– Microsoft Windows 2000 Professional SP2
– Microsoft Windows 2000 Professional SP1
– Microsoft Windows 2000 Professional
– Microsoft Windows 98
– Microsoft Windows ME
– Microsoft Windows NT Workstation 4.0 SP6a
– Microsoft Windows NT Workstation 4.0 SP6
– Microsoft Windows NT Workstation 4.0 SP5
– Microsoft Windows NT Workstation 4.0 SP4
– Microsoft Windows NT Workstation 4.0 SP3
– Microsoft Windows NT Workstation 4.0 SP2
– Microsoft Windows NT Workstation 4.0 SP1
– Microsoft Windows NT Workstation 4.0
– Microsoft Windows XP Home
– Microsoft Windows XP Professional Microsoft Office 2004 for Mac 0 Microsoft Office 2003 SP2 Microsoft Office 2003 SP1 Microsoft Office 2003 0
+ Microsoft Excel 2003
+ Microsoft FrontPage 2003
+ Microsoft InfoPath 2003
+ Microsoft OneNote 2003 0
+ Microsoft Outlook 2003 0
+ Microsoft PowerPoint 2003 0
+ Microsoft Publisher 2003 Microsoft Office 2000 SP3
– Microsoft Windows 2000 Professional SP3
– Microsoft Windows 2000 Professional SP2
– Microsoft Windows 2000 Professional SP1
– Microsoft Windows 2000 Professional
– Microsoft Windows 98
– Microsoft Windows 98SE
– Microsoft Windows ME
– Microsoft Windows NT Workstation 4.0 SP6a
– Microsoft Windows NT Workstation 4.0 SP6
– Microsoft Windows NT Workstation 4.0 SP5
– Microsoft Windows NT Workstation 4.0 SP4
– Microsoft Windows NT Workstation 4.0 SP3
– Microsoft Windows NT Workstation 4.0 SP2
– Microsoft Windows NT Workstation 4.0 SP1
– Microsoft Windows NT Workstation 4.0
– Microsoft Windows XP Home SP1
– Microsoft Windows XP Home
– Microsoft Windows XP Professional SP1
– Microsoft Windows XP Professional Microsoft Office 2000 SP1
– Microsoft Windows 2000 Professional SP2
– Microsoft Windows 2000 Professional SP1
– Microsoft Windows 2000 Professional
– Microsoft Windows ME
– Microsoft Windows NT Workstation 4.0 SP6a
– Microsoft Windows NT Workstation 4.0 SP6
– Microsoft Windows NT Workstation 4.0 SP5
– Microsoft Windows NT Workstation 4.0 SP4
– Microsoft Windows NT Workstation 4.0 SP3
– Microsoft Windows NT Workstation 4.0 SP2
– Microsoft Windows NT Workstation 4.0 SP1
– Microsoft Windows NT Workstation 4.0
– Microsoft Windows XP Home
– Microsoft Windows XP Professional Microsoft Office 2000
– Microsoft Windows 2000 Professional SP2
– Microsoft Windows 2000 Professional SP1
– Microsoft Windows 2000 Professional
– Microsoft Windows 95
– Microsoft Windows 98
– Microsoft Windows ME
– Microsoft Windows NT Workstation 4.0 SP6a
– Microsoft Windows NT Workstation 4.0 SP6
– Microsoft Windows NT Workstation 4.0 SP5
– Microsoft Windows NT Workstation 4.0 SP4
– Microsoft Windows NT Workstation 4.0 SP3
– Microsoft Windows NT Workstation 4.0 SP2
– Microsoft Windows NT Workstation 4.0 SP1
– Microsoft Windows NT Workstation 4.0
– Microsoft Windows XP Home
– Microsoft Windows XP Professional Microsoft Internet Explorer for Unix SP2 |
–
漏洞讨论
| Microsoft Office is prone to a remote memory-corruption vulnerability. An attacker could exploit this issue by enticing a victim to open a malicious Office file. Successfully exploiting this issue would allow the attacker to execute arbitrary code in the context of the currently logged-in user. |
–
漏洞利用
|
Exploit code is available. Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild. |
–
解决方案
|
The vendor released an advisory and updates. Please see the references for more information. Microsoft Office XP SP3
|
–
相关参考
|




![[单曲] 《千滴泪》——2007华语流行最伤感情歌-微慑信息网-VulSee.com](http://www.6778.com/gif/07%2B/Line/line4-8.gif)

![[八卦] 王婷婷—揭秘一个大三女生的性爱录像-微慑信息网-VulSee.com](http://free.86hy.com/crack/pic/1.jpg)
![[随笔]今天国际警察节-微慑信息网-VulSee.com](http://photo.sohu.com/20041017/Img222528326.jpg)

青云网
