Privacy and Legal Notice

CIAC INFORMATION BULLETIN

R-232: Vulnerability in Microsoft Office

[Microsoft Security Bulletin MS07-025 (934873)]

May 9, 2007 12:00 GMT
[REVISED 17 May 2007]
[REVISED 21 may 2007]
[REVISED 28 Mar 2008]
[REVISED 1 May 2008]

PROBLEM: A remote code execution vulnerability exists in the way Microsoft Office handles a specially crafted drawing object.
PLATFORM: Tested Software and Security Update Download Locations:
Affected Software:
• Microsoft Office 2000 Service Pack 3
  • Microsoft Excel 2000
  • Microsoft FrontPage 2000
  • Microsoft Publisher 2000
• Microsoft Office XP Service Pack 3
  • Microsoft Excel 2002
  • Microsoft FrontPage 2002
  • Microsoft Publisher 2002
• Microsoft Office 2003 Service Pack 2
  • Microsoft Excel 2003
  • Microsoft FrontPage 2003
  • Microsoft Publisher 2003
  • Microsoft Excel 2003 Viewer
• 2007 Microsoft Office System
  • Microsoft Office Excel 2007
  • Microsoft Office Publisher 2007
  • Microsoft Office SharePoint Designer 2007
  • Microsoft Expression Web
• Microsoft Office 2004 for Mac
  • Microsoft Office Compatibility Pack
  • Word, Excel, and PowerPoint 2007 File Formats

Non-Affected Software:
• Microsoft Works Suites:
  • Microsoft Works Suite 2004
  • Microsoft Works Suite 2005
  • Microsoft Works Suite 2006
• Microsoft Office 2000 Service Pack 3
  • Microsoft Access 2000
  • Microsoft Outlook 2000
  • Microsoft PowerPoint 2000
  • Microsoft Project 2000 Service Release 1
  • Microsoft Word 2000
• Microsoft Office XP Service Pack 3
  • Microsoft Access 2002
  • Microsoft Outlook 2002
  • Microsoft PowerPoint 2002
  • Microsoft Project 2002 Service Pack 1
  • Microsoft Visio 2002
  • Microsoft Word 2002
• Microsoft Office 2003 Service Pack 2:
  • Microsoft Access 2003
  • Microsoft InfoPath 2003
  • Microsoft OneNote 2003
  • Microsoft Outlook 2003
  • Microsoft Project 2003
  • Microsoft PowerPoint 2003
  • Microsoft PowerPoint 2003 Viewer
  • Microsoft Visio 2003
  • Microsoft Word 2003
  • Microsoft Word 2003 Viewer
• 2007 Microsoft Office System
  • Microsoft Office Access 2007
  • Microsoft Office PowerPoint 2007
  • Microsoft Office Project 2007
  • Microsoft Office Visio 2007
  • Microsoft Office Word 2007
  • Word, Excel, and PowerPoint 2007 File Formats Service Pack 1
DAMAGE: Could allow remote code execution.
SOLUTION: Upgrade to the appropriate version.

VULNERABILITY
ASSESSMENT:
The risk is MEDIUM. Code runs in the context of the user.

LINKS:  
  CIAC BULLETIN: http://www.ciac.org/ciac/bulletins/r-232.shtml
  ORIGINAL BULLETIN: http://www.microsoft.com/technet/security/Bulletin/MS07-025.mspx
  CVE: CVE-2007-1747

REVISION HISTORY:
	05/17/2007 - revised R-232 to reflect changes Microsoft has made in MS07-025 where
                 they updated the workaround section with the removal of the "Use 
				 Microsoft Word Viewer 2003 to open and view files" workaround. 
    05/21/2007 - revised R-232 to reflect changes Microsoft has made in MS07-025 where
                 they updated due to new issues discovered with the security update as 
				 reflected in Microsoft Knowledge Base Article 934873.
    03/28/2008 - revised R-232 to reflect changes Microsoft has made in MS07-025 where
                 they added Microsoft Office Compatibility Pack for Word, Excel, and 
				 PowerPoint 2007 File Formats and Microsoft Office Compatibility Pack 
				 for Word, Excel, and PowerPoint 2007 File Formats Service Pack 1 to 
				 the Affected Software list.
    05/01/2008 - revised R-232 to reflect changes Microsoft has made in MS07-025 where
                 they moved Microsoft Office Compatibility Pack for Word, Excel, and 
				 PowerPoint 2007 File Formats Service Pack 1 from the Affected Software 
				 list to the Non-Affected Software list.



[***** Start Microsoft Security Bulletin MS07-025 (934873) *****]


Microsoft Security Bulletin MS07-025

Vulnerability in Microsoft Office Could Allow Remote Code Execution (934873)

Published: May 8, 2007 | Updated: April 30, 2008

Version: 2.1

Summary

Who Should Read this Document: Customers who use Microsoft Office

Impact of Vulnerability: Remote Code Execution

Maximum Severity Rating: Critical

Recommendation: Customers should apply the update immediately

Security Update Replacement: This bulletin replaces a prior security update. See the Frequently Asked Questions (FAQ) section of this bulletin for details.

Caveats: None

Tested Software and Security Update Download Locations:

Affected Software:

Microsoft Office 2000 Service Pack 3 — Download the update (KB934526)

Microsoft Excel 2000

Microsoft FrontPage 2000

Microsoft Publisher 2000

Microsoft Office XP Service Pack 3 — Download the update (KB934705)

Microsoft Excel 2002

Microsoft FrontPage 2002

Microsoft Publisher 2002

Microsoft Office 2003 Service Pack 2 — Download the update (KB934180)

Microsoft Excel 2003

Microsoft FrontPage 2003

Microsoft Publisher 2003

Microsoft Excel 2003 Viewer

2007 Microsoft Office System — Download the update (KB934062)

Microsoft Office Excel 2007

Microsoft Office Publisher 2007

Microsoft Office SharePoint Designer 2007

Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats

Microsoft Expression Web

Microsoft Office 2004 for Mac — Download the update (KB936749)

 

Non-Affected Software:

Microsoft Works Suites:

Microsoft Works Suite 2004

Microsoft Works Suite 2005

Microsoft Works Suite 2006

Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Service Pack 1

Microsoft Office 2000 Service Pack 3

Microsoft Access 2000

Microsoft Outlook 2000

Microsoft PowerPoint 2000

Microsoft Project 2000 Service Release 1

Microsoft Word 2000

Microsoft Office XP Service Pack 3

Microsoft Access 2002

Microsoft Outlook 2002

Microsoft PowerPoint 2002

Microsoft Project 2002 Service Pack 1

Microsoft Visio 2002

Microsoft Word 2002

Microsoft Office 2003 Service Pack 2:

Microsoft Access 2003

Microsoft InfoPath 2003

Microsoft OneNote 2003

Microsoft Outlook 2003

Microsoft Project 2003

Microsoft PowerPoint 2003

Microsoft PowerPoint 2003 Viewer

Microsoft Visio 2003

Microsoft Word 2003

Microsoft Word 2003 Viewer

2007 Microsoft Office System

Microsoft Office Access 2007

Microsoft Office PowerPoint 2007

Microsoft Office Project 2007

Microsoft Office Visio 2007

Microsoft Office Word 2007

The software in this list has been tested to determine whether the versions are affected. Other versions are either past their support life cycle or are not affected. To determine the support life cycle for your product and version, visit the Microsoft Support Lifecycle Web site.

Top of sectionTop of section

General Information

Executive Summary

Executive Summary:

This update resolves a privately reported vulnerability. The vulnerability is documented in its own subsection in the Vulnerability Details section of this bulletin.

An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

When using vulnerable versions of Office, if a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of the system. An attacker could then install programs; view, change, or delete data; or create new accounts with the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

We recommend that customers apply the update immediately.

Severity Ratings and Vulnerability Identifiers:

Vulnerability Identifiers Impact of Vulnerability Microsoft Office 2000 Service Pack 3 Microsoft Office XP Service Pack 3 Microsoft Office 2003 Service Pack 2 2007 Microsoft Office System Microsoft Office 2004 for Mac

Drawing Object Vulnerability - CVE-2007-1747

Remote Code Execution

Critical

Important

Important

Important

Important

This assessment is based on the types of systems that are affected by the vulnerability, their typical deployment patterns, and the effect that exploiting the vulnerability would have on them.

Frequently Asked Questions (FAQ) Related to This Security Update

Vulnerability Details

Drawing Object Vulnerability - CVE-2007-1747:

A remote code execution vulnerability exists in the way Microsoft Office handles a specially crafted drawing object. An attacker could exploit this vulnerability when Office parses a file and processes a malformed drawing object. Such a specially crafted file might be included as an e-mail attachment or hosted on a malicious Web site. An attacker could exploit the vulnerability by constructing a specially crafted Office file containing a malformed drawing object that could allow remote code execution.

Mitigating Factors for Drawing Object Vulnerability - CVE-2007-1747:
Workarounds for Drawing Object Vulnerability - CVE-2007-1747:
FAQ for Drawing Object Vulnerability - CVE-2007-1747:

Security Update Information

Affected Software:

For information about the specific security update for your affected software, click the appropriate link:

Office 2000

Office XP