Microsoft Windows Knowledge Base Article 978214 update is not installed (WinMs10kb978214Update)

Vuln ID: 55932
Risk Level: High risk vulnerability  High WinMs10kb978214Update
Platforms: Microsoft Office: XP SP3, Microsoft Office: 2004 Mac OS
Description:

Microsoft Windows Knowledge Base Article 978214 update is not installed on the system, which could allow an attacker to exploit the following vulnerability:

Microsoft Office is vulnerable to a buffer overflow, caused by improper bounds checking when processing Office files. By persuading a victim to open a specially-crafted Office file, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.

Remedy:

Apply the appropriate patch for your system, as listed in Microsoft Security Bulletin MS10-003. See References.

False Positives:
False Negatives:
Required Permission: Windows login
Additional Information:

References:

Microsoft Security Bulletin MS10-003
Vulnerability in Microsoft Office (MSO) Could Allow Remote Code Execution (978214)
http://www.microsoft.com/technet/security/bulletin/ms10-003.mspx

IBM Internet Security Systems X-Force Database
Microsoft Office Office files buffer overflow
http://xforce.iss.net/xforce/xfdb/55931

ISS X-Force
Microsoft Windows Knowledge Base Article 978214 update is not installed
http://www.iss.net/security_center/static/55932.php

CVE CVE-2010-0243
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0243


X-Force Logo
Know Your Risks
Mitre.org CVE Logo
Common Vulnerabilties & Exposures