header-logo
Suggest Exploit
vendor:
Microsoft Word 2007
by:
Muts
N/A
CVSS
N/A
Unspecified Overflow, CPU Exhaustion DOS
Unknown
CWE
Product Name: Microsoft Word 2007
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE:
Metasploit:
Other Scripts:
Platforms Tested:
2007

File Format Bugs in Word 2007

My 7 line python fuzzer found several file format bugs in 3 hours. No deep analysis was done. These bugs include an Unspecified Overflow in word 2007 which can lead to a crash in wwlib.dll. Another bug causes CPU exhaustion DOS, where the CPU shoots up to 100%. There is also a bug that causes CPU exhaustion DOS and triggers the Windows system sound .ding!.

Mitigation:

Unknown
Source

Exploit-DB raw data:

# Mati Aharoni

# muts [.@.] offensive-security.com

# http://www.offensive-security.com

 

 

My 7 line python fuzzer found several file format bugs in 3 hours. Quite alarming.

No deep analysis was done, I leave that to the community.

These are some of the results:

 

file789-1.doc  - Unspecified Overflow in word 2007 - Crash in wwlib.dll . Code execution is not trivial.

file798-1.doc . Word 2007 CPU exhaustion DOS - CPU shoots up to 100 %.

file613-1.doc -  Word 2007 CPU exhaustion DOS + ding - CPU shoots up to 100 %, and windows goes .ding!.

 

These files can be found at http://www.offensive-security.com/0day/0day.tar.gz

backup: https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/3690.tar.gz (04092007-0day.tar.gz)
 

Be safe,

 

Muts


# milw0rm.com [2007-04-09]
cqrsecured