TITLE: Microsoft Word Unspecified Memory Corruption Vulnerability SECUNIA ADVISORY ID: SA28901 VERIFY ADVISORY: http://secunia.com/advisories/28901/ CRITICAL: Highly critical IMPACT: System access WHERE: From remote SOFTWARE: Microsoft Word Viewer 2003 http://secunia.com/product/5523/ Microsoft Word 2003 http://secunia.com/product/4908/ Microsoft Word 2002 http://secunia.com/product/2150/ Microsoft Word 2000 http://secunia.com/product/2149/ Microsoft Office XP http://secunia.com/product/23/ Microsoft Office 2003 Student and Teacher Edition http://secunia.com/product/2278/ Microsoft Office 2003 Standard Edition http://secunia.com/product/2275/ Microsoft Office 2003 Small Business Edition http://secunia.com/product/2277/ Microsoft Office 2003 Professional Edition http://secunia.com/product/2276/ Microsoft Office 2000 http://secunia.com/product/24/ DESCRIPTION: A vulnerability has been reported in Microsoft Word, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to a calculation error when parsing Word documents and can be exploited to corrupt memory via a specially crafted Word file. Successful exploitation allows execution of arbitrary code. SOLUTION: Apply patches. Microsoft Word 2000 SP3: http://www.microsoft.com/downloads/details.aspx?FamilyId=A513069B-8244-48E9-B136-01DDD3862802 Microsoft Word 2002 SP3: http://www.microsoft.com/downloads/details.aspx?FamilyId=78C338AA-E410-4422-9E36-562F70D742E9 Microsoft Word 2003 SP2: http://www.microsoft.com/downloads/details.aspx?FamilyId=85CB1AA5-211F-4652-827B-2E79B8FFC2FC Microsoft Office Word Viewer 2003: http://www.microsoft.com/downloads/details.aspx?FamilyId=FD4DDECD-ABD6-4783-B300-32B9D4BAD22A ORIGINAL ADVISORY: MS08-008 (KB947077): http://www.microsoft.com/technet/security/Bulletin/MS08-009.mspx ========================= The list's FAQ's can be seen by sending an email to PCWorks-request@xxxxxxxxxxxxx with FAQ in the subject line. To unsubscribe, subscribe, set Digest or Vacation to on or off, go to //www.freelists.org/list/pcworks . You can also send an email to PCWorks-request@xxxxxxxxxxxxx with Unsubscribe in the subject line. Your member list settings can be found at //www.freelists.org/cgi-bin/lsg2.cgi/l=pcworks . Once logged in, you have access to numerous other email options. The list archives are located at //www.freelists.org/archives/pcworks/ . All email posted to the list will be placed there in the event anyone needs to look for previous posts.