This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Community Information

Two new MS exploits....

1 min read

This thread's last reply is from July 13, 2005, 12:09 AM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

"Microsoft Word Font Parsing Buffer Overflow Vulnerability

Lord Yup has reported a vulnerability in Microsoft Word, which can be
exploited by malicious people to compromise a user's system.

The vulnerability is caused due to a boundary error within the
parsing of fonts. This can be exploited to cause a stack-based buffer
overflow by tricking a user into opening a specially crafted Word
document.

Successful exploitation allows execution of arbitrary code."


Secunia Advisory

==============

"Microsoft Windows Color Management Module Buffer Overflow

A vulnerability has been reported in Microsoft Windows, which can be
exploited by malicious people to compromise a vulnerable system.

The vulnerability is caused due to a boundary error within the color
management module when validating ICC profile format tags. This can
be exploited to cause a buffer overflow by e.g. tricking a user into
visiting a malicious web site or view a malicious e-mail message
containing a specially crafted image file.

Successful exploitation allows execution of arbitrary code."


Secunia Advisory
Bump