int(5324)

Vulnerability Bulletins


Ejecución de código arbitrario en Microsoft Office

Vulnerability classification

Property Value
Confidence level Oficial
Impact Obtener acceso
Dificulty Experto
Required attacker level Acceso remoto sin cuenta a un servicio estandar

System information

Property Value
Affected manufacturer Microsoft
Affected software Microsoft Office XP SP3
Microsoft Office 2003 SP3
Microsoft Office 2007 SP1 y SP2

Description

Se ha descubierto una vulnerabilidad en Microsoft Office XP SP3, 2003 SP3 y 2007 SP1 y SP2. La vulnerabilidad reside en un error en la instanciación del objeto COM.

Un atacante remoto podría ejecutar código arbitrario mediante la manipulación de un fichero Office.

Este boletín reemplaza a los boletines: MS08-055, MS10-017, MS10-004, MS10-023, MS10-028, MS09-068, MS09-017 y MS09-027.

Solution



Actualización de software

Microsoft (MS10-036)
Microsoft Office 2003 SP3 / Microsoft Office Excel 2003 SP3 / patch office2003-KB982133-FullFile-ENU
Microsoft Office 2003 SP3 / Microsoft Office PowerPoint 2003 SP3 / patch office2003-KB982157-FullFile-ENU
Microsoft Office 2003 SP3 / Microsoft Office Publisher 2003 SP3 / patch office2003-KB982122-FullFile-ENU
Microsoft Office 2003 SP3 / Microsoft Office Visio 2003 SP3 / patch visio2003-KB982126-FullFile-ENU
Microsoft Office 2003 SP3 / Microsoft Office Word 2003 SP3 / patch office2003-KB982134-FullFile-ENU
2007 Microsoft Office SP1 y 2007 Microsoft Office SP2 / Microsoft Office Excel 2007 SP 1 y Microsoft Office Excel 2007 SP2 / patch excel2007-kb982308-fullfile-x86-glb
2007 Microsoft Office SP1 y 2007 Microsoft Office SP2 / Microsoft Office PowerPoint 2007 SP1 y Microsoft Office PowerPoint 2007 SP2 / patch powerpoint2007-kb982158-fullfile-x86-glb
2007 Microsoft Office SP1 y 2007 Microsoft Office SP2 / Microsoft Office Publisher 2007 SP1 y Microsoft Office Publisher 2007 SP2 / patch publisher2007-kb982124-fullfile-x86-glb
2007 Microsoft Office SP1 y 2007 Microsoft Office SP2 / Microsoft Office Visio 2007 SP1 y Microsoft Office Visio 2007 SP2 / patch visio2007-kb982127-fullfile-x86-glb
2007 Microsoft Office SP1 y 2007 Microsoft Office SP2 / Microsoft Office Word 2007 SP1 y Microsoft Office Word 2007 SP2 / patch word-kb982135-fullfile-x86-glb
http://www.microsoft.com/downloads

Standar resources

Property Value
CVE CVE-2010-1263
BID

Other resources

Microsoft Security Bulletin (MS10-036)
http://www.microsoft.com/technet/security/bulletin/MS10-036.mspx

Version history

Version Comments Date
1.0 Avido emitido 2010-06-09
Ministerio de Defensa
CNI
CCN
CCN-CERT