EH-Net

Ethical Hacking Discussions and Related Certifications => Malware => Topic started by: Equix3n- on July 14, 2009, 08:16:08 AM



Title: Microsoft Office Web Components Zero Day
Post by: Equix3n- on July 14, 2009, 08:16:08 AM
Quote
Description:
A vulnerability has been reported in Microsoft Office Web Components, which can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to an unspecified error in the Spreadsheet ActiveX control and can be exploited to corrupt memory.

Successful exploitation allows execution of arbitrary code.

NOTE: According to Microsoft, the vulnerability is currently being actively exploited.

Read more:
http://secunia.com/advisories/35800/

http://www.microsoft.com/technet/security/advisory/973472.mspx

http://blogs.technet.com/srd/archive/2009/07/13/more-information-about-the-office-web-components-activex-vulnerability.aspx