Microsoft Windows Knowledge Base Article 969514 update is not installed (WinMs09kb969514Update)

Vuln ID: 50795
Risk Level: High risk vulnerability  High WinMs09kb969514Update
Platforms: Microsoft Office: 2000 SP3, Microsoft Works: 8.5, Microsoft Office: 2003 SP3, Microsoft Office: 2002 SP3, Microsoft Office Word Viewer, Microsoft Office Word Viewer: 2003 SP3, Microsoft Office Compatibility Pack: 2007 SP1, Microsoft Office: 2007 SP1, Microsoft Office Compatibility Pack: 2007 SP2, Microsoft Works: 9.0, Microsoft Office: 2007 SP2, Microsoft Office: 2004 Mac OS, Microsoft Office: 2008 Mac OS, Microsoft Open XML File Format Converter: Mac OS
Description:

Microsoft Knowledge Base Article 969514 is not installed, which could allow a remote attacker to exploit the following vulnerabilities:

Microsoft Word is vulnerable to a buffer overflow. By persuading a victim to open a specially-crafted Word file containing a malformed record with Microsoft Office Word, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.

Microsoft Word is vulnerable to a buffer overflow. By persuading a victim to open a specially-crafted Word file with Microsoft Office Word, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.

Remedy:

Apply the appropriate patch for your system, as listed in Microsoft Security Bulletin MS09-027. See References.

False Positives:
False Negatives:
Required Permission: Windows login
Additional Information:

References:

Microsoft Security Bulletin MS09-027
Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution (969514)
http://www.microsoft.com/technet/security/bulletin/ms09-027.mspx

IBM Internet Security Systems X-Force Database
Microsoft Word Word file buffer overflow
http://xforce.iss.net/xforce/xfdb/50793

IBM Internet Security Systems X-Force Database
Microsoft Word Word file buffer overflow
http://xforce.iss.net/xforce/xfdb/50794

ISS X-Force
Microsoft Windows Knowledge Base Article 969514 update is not installed
http://www.iss.net/security_center/static/50795.php

CVE CVE-2009-0563
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0563

CVE CVE-2009-0565
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0565


X-Force Logo
Know Your Risks
Mitre.org CVE Logo
Common Vulnerabilties & Exposures