Privacy and Legal Notice

CIAC INFORMATION BULLETIN

R-010: Vulnerabilities in Microsoft Word

[Microsoft Security Bulletin MS06-060 (924554)]

October 10, 2006 19:00 GMT
[REVISED 19 Oct 2006]
[REVISED 14 Nov 2006]

PROBLEM: A remote code execution vulnerability exists in Microsoft Word.
PLATFORM: Tested Software and Security Update Download Locations:
Affected Software:
• Microsoft Office 2000 Service Pack 3
• Microsoft Word 2000
• Microsoft Office XP Service Pack 3
• Microsoft Word 2002
• Microsoft Office 2003 Service Pack 1 or Service Pack 2
• Microsoft Office Word 2003
• Microsoft Office Word 2003 Viewer
• Microsoft Works Suites:
• Microsoft Works Suite 2004
• Microsoft Works Suite 2005
• Microsoft Works Suite 2006
• Microsoft Office 2004 for Mac
• Microsoft Office v. X for Mac
Storage Management Appliance v2.1 Software running on I, II, III
DAMAGE: An attacker cold take complete control of an affected system.
SOLUTION: Upgrade to the appropriate version.

VULNERABILITY
ASSESSMENT:
The risk is HIGH. An attacker cold take complete control of an affected system.

LINKS:  
  CIAC BULLETIN: http://www.ciac.org/ciac/bulletins/r-010.shtml
  ORIGINAL BULLETIN: Microsoft Security Bulletin MS06-060
   http://www.microsoft.com/technet/security/Bulletin/MS06-060.mspx
  ADDITIONAL LINK: Visit Hewlett-Packard Subscription Service for:
HPSBST02161 SSRT061264 rev. 1
Debian Security Advisory 1208-1
http://www.debian.org/security/2006/dsa-1208
  CVE: CVE-2006-3647, CVE-2006-3651, CVE-2006-4534, CVE-2006-4693

REVISION HISTORY:
10/19/2006 - revised R-010 to add a link to Hewlett-Packard HPSBST01261 SSRT061264 rev. 1 for 
             Storage Management Appliance Software v2.1 Software running on I, II, III
11/14/2006 - added a link to Debian Security Advisory 1208-1
			 
			 
			 
			 
[***** Start Microsoft Security Bulletin MS06-060 (924554) *****]



Microsoft Security Bulletin MS06-060

Vulnerabilities in Microsoft Word Could Allow Remote Code Execution (924554)

Published: October 10, 2006

Version: 1.0

Summary

Who Should Read this Document: Customers who use Microsoft Word

Impact of Vulnerability: Remote Code Execution

Maximum Severity Rating: Critical

Recommendation: Customers should apply the update immediately

Security Update Replacement: This bulletin replaces a prior security update. See the frequently asked questions (FAQ) section of this bulletin for the complete list.

Caveats: None

Tested Software and Security Update Download Locations:

Affected Software:

Microsoft Office 2000 Service Pack 3 - Download the update (KB920910)

Microsoft Word 2000

Microsoft Office XP Service Pack 3 - Download the update (KB920817)

Microsoft Word 2002

Microsoft Office 2003 Service Pack 1 or Service Pack 2 - Download the update (KB923094)

Microsoft Office Word 2003

Microsoft Office Word 2003 Viewer - Download the update (KB923276)

Microsoft Works Suites:

Microsoft Works Suite 2004 - Download the update (KB920817) (same as the Microsoft Word 2002 update)

Microsoft Works Suite 2005 - Download the update (KB920817) (same as the Microsoft Word 2002 update)

Microsoft Works Suite 2006 - Download the update (KB920817) (same as the Microsoft Word 2002 update)

Microsoft Office 2004 for Mac - Download the update (KB924999)

Microsoft Office v. X for Mac- Download the update (KB924998)

The software in this list has been tested to determine whether the versions are affected. Other versions either no longer include security update support or may not be affected. To determine the support life cycle for your product and version, visit the Microsoft Support Lifecycle Web site.

Top of sectionTop of section

General Information

Executive Summary

Frequently Asked Questions (FAQ) Related to This Security Update

Vulnerability Details

Security Update Information