vendor:
Microsoft Office 2007
by:
Google Security Research
7,8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Microsoft Office 2007
Affected Version From: Microsoft Office 2007
Affected Version To: Microsoft Office 2007
Patch Exists: YES
Related CWE: N/A
CPE: microsoft:office:2007
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2015
Microsoft Office 2007 with Microsoft Office File Validation Add-In disabled and Application Verifier enabled
When run without Application Verifier enabled, a buffer overflow vulnerability was observed in Microsoft Office 2007 with Microsoft Office File Validation Add-In disabled and Application Verifier enabled. This bug did not reproduce in Office 2010 or 2013. The minimized crashing file shows a one bit deltas from the original file at offset 0x49E8. OffVis reports this to be the CreateTime field of an OLESSDirectoryEntry structure. The global variable dword_30F5F9BC is pointing to a structure which is corrupted, resulting in a buffer overflow.
Mitigation:
Application Verifier should be enabled to prevent buffer overflow.