Privacy and Legal Notice

CIAC INFORMATION BULLETIN

R-131: Vulnerabilities in Microsoft Office (932554)

[Microsoft Security Bulletin MS07-015]

February 14, 2007 12:00 GMT
[REVISED 1 Mar 2007]
[REVISED 24 Apr 2008]

PROBLEM: Vulnerabilities exist in Microsoft PowerPoint and Excel that could allow remote code execution.
PLATFORM: Tested Software and Security Update Download Locations:
Affected Software:
Microsoft Office 2000 Service Pack 3 — Download the update (KB 929062)
  • Microsoft Access 2000
  • Microsoft Excel 2000
  • Microsoft FrontPage 2000
  • Microsoft Outlook 2000
  • Microsoft PowerPoint 2000
  • Microsoft Publisher 2000
  • Microsoft Word 2000
• Microsoft Office XP Service Pack 3 — Download the update (KB929063)
  • Microsoft Access 2002
  • Microsoft Excel 2002
  • Microsoft FrontPage 2002
  • Microsoft Outlook 2002
  • Microsoft PowerPoint 2002
  • Microsoft Publisher 2002
  • Microsoft Word 2002
• Microsoft Office 2003 Service Pack 2 — Download the update (KB929064)
  • Microsoft Access 2003
  • Microsoft Excel 2003
  • Microsoft Excel 2003 Viewer
  • Microsoft FrontPage 2003
  • Microsoft InfoPath 2003
  • Microsoft OneNote 2003
  • Microsoft Outlook 2003
  • Microsoft PowerPoint 2003
  • Microsoft Project 2003
  • Microsoft Publisher 2003
  • Microsoft Visio 2003
  • Microsoft Word 2003
  • Microsoft Excel 2003 Viewer
  • Microsoft Word 2003 Viewer
• Microsoft Project 2000 Service Release 1 — Download the update (KB929062)
• Microsoft Project 2002 Service Pack 1 — Download the update (KB929063)
• Microsoft Visio 2002 Service Pack 2 — Download the update (KB929063)
• Microsoft Office 2004 for Mac — Download the update (KB932185)

Non-Affected Software:
• 2007 Microsoft Office System
• Microsoft Office 2003 Service Pack 2
  • Microsoft PowerPoint 2003 Viewer
• Microsoft Works Suites:
  • Microsoft Works Suite 2004
  • Microsoft Works Suite 2005
  • Microsoft Works Suite 2006

DAMAGE: Could allow remote code execution.
SOLUTION: Upgrade to the appropriate version.

VULNERABILITY
ASSESSMENT:
The risk is MEDIUM. An intruder who can coerce a user to open a malicious PowerPoint or Excel document can run arbitrary code in the security context of the logged-in user.

LINKS:  
  CIAC BULLETIN: http://www.ciac.org/ciac/bulletins/r-131.shtml
  ORIGINAL BULLETIN: http://www.microsoft.com/technet/security/Bulletin/MS07-015.mspx
  CVE: CVE-2006-3877 CVE-2007-0671

REVISION HISTORY:
	03/01/2007 - revised R-131 to reflect changes Microsoft has made on MS07-015 
                 where tehy updated "Prerequisites and Additional Update" for Office 
				 2003 in the "Security Update Information" section.
	04/24/2008 - revised R-131 to reflect changes Microsoft has made on MS07-015 
                 where they updated Microsoft Visio 2002 removed from Microsoft 
				 Office XP Service Pack 3 section of Affected Software table. 
				 Microsoft Visio 2002 Service Pack 2 is listed spearately in the 
				 Affected Software table. 
				 
				 
[***** Start Microsoft Security Bulletin MS07-015 *****]



Microsoft Security Bulletin MS07-015

Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (932554)

Published: February 13, 2007 | Update: April 24, 2008

Version: 1.2

Summary

Who Should Read this Document: Customers who use Microsoft Office

Impact of Vulnerability: Remote Code Execution

Maximum Severity Rating: Critical

Recommendation: Customers should apply the update immediately

Security Update Replacement: This bulletin replaces a prior security update. See the frequently asked questions (FAQ) section of this bulletin for the complete list.

Caveats: None

Tested Software and Security Update Download Locations:

Affected Software:

Microsoft Office 2000 Service Pack 3 — Download the update (KB 929062)

Microsoft Access 2000

Microsoft Excel 2000

Microsoft FrontPage 2000

Microsoft Outlook 2000

Microsoft PowerPoint 2000

Microsoft Publisher 2000

Microsoft Word 2000

Microsoft Office XP Service Pack 3 — Download the update (KB929063)

Microsoft Access 2002

Microsoft Excel 2002

Microsoft FrontPage 2002

Microsoft Outlook 2002

Microsoft PowerPoint 2002

Microsoft Publisher 2002

Microsoft Word 2002

Microsoft Office 2003 Service Pack 2 — Download the update (KB929064)

Microsoft Access 2003

Microsoft Excel 2003

Microsoft Excel 2003 Viewer

Microsoft FrontPage 2003

Microsoft InfoPath 2003

Microsoft OneNote 2003

Microsoft Outlook 2003

Microsoft PowerPoint 2003

Microsoft Project 2003

Microsoft Publisher 2003

Microsoft Visio 2003

Microsoft Word 2003

Microsoft Excel 2003 Viewer

Microsoft Word 2003 Viewer

Microsoft Project 2000 Service Release 1 — Download the update (KB929062)

Microsoft Project 2002 Service Pack 1 — Download the update (KB929063)

Microsoft Visio 2002 Service Pack 2 — Download the update (KB929063)

Microsoft Office 2004 for Mac — Download the update (KB932185)

 

Non-Affected Software:

2007 Microsoft Office System

Microsoft Office 2003 Service Pack 2

Microsoft PowerPoint 2003 Viewer

Microsoft Works Suites:

Microsoft Works Suite 2004

Microsoft Works Suite 2005

Microsoft Works Suite 2006

The software in this list has been tested to determine whether the versions are affected. Other versions either no longer include security update support or may not be affected. To determine the support life cycle for your product and version, visit the Microsoft Support Lifecycle Web site.

Top of sectionTop of section

General Information

Executive Summary

Executive Summary:

This update resolves two newly discovered, privately and publicly reported vulnerabilities. Each vulnerability is documented in its own subsection in the "Vulnerability Details" section of this bulletin.

When using vulnerable versions of Office, if a user were logged on with administrative user rights, an attacker who successfully exploited these vulnerabilities could take complete control of the system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

We recommend that customers apply the update immediately.

Severity Ratings and Vulnerability Identifiers:

Vulnerability Identifiers Impact of Vulnerability Microsoft Office 2000 Microsoft Office XP Microsoft Office 2003 Microsoft Office 2004 for Mac

PowerPoint Malformed Record Memory Corruption Vulnerability - CVE-2006-3877

Remote Code Execution

Critical

Important

Important

Important

Excel Malformed Record Vulnerability - CVE-2007-0671

Remote Code Execution

Critical

Important

Important

Important

This assessment is based on the types of systems that are affected by the vulnerability, their typical deployment patterns, and the effect that exploiting the vulnerability would have on them.

Frequently Asked Questions (FAQ) Related to This Security Update

Vulnerability Details

PowerPoint Malformed Record Memory Corruption Vulnerability - CVE-2006-3877:

A remote code execution vulnerability exists in PowerPoint and could be exploited when PowerPoint opened a specially crafted file. Such a file might be included in an e-mail attachment or hosted on a malicious web site. An attacker could exploit the vulnerability by constructing a specially crafted PowerPoint file that could allow remote code execution.

If a user were logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less affected than users who operate with administrative user rights.

Mitigating Factors for PowerPoint Malformed Record Memory Corruption Vulnerability - CVE-2006-3877:
Workarounds for PowerPoint Malformed Record Memory Corruption Vulnerability - CVE-2006-3877:
FAQ for PowerPoint Malformed Record Memory Corruption Vulnerability - CVE-2006-3877:

Excel Malformed Record Vulnerability - CVE-2007-0671:

A remote code execution vulnerability exists in Excel and could be exploited when Excel opened a specially crafted file. Such a file might be included in an e-mail attachment or hosted on a malicious web site. An attacker could exploit the vulnerability by constructing a specially crafted Excel file that could allow remote code execution.

If a user were logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less affected than users who operate with administrative user rights.

Mitigating Factors for Excel Malformed Record Vulnerability - CVE-2007-0671:
Workarounds for Excel Malformed Record Vulnerability - CVE-2007-0671:
FAQ for Excel Malformed Record Vulnerability - CVE-2007-0671:

Security Update Information

Affected Software:

For information about the specific security update for your affected software, click the appropriate link:

Office 2000

Office XP