vendor:
Office
by:
Google Security Research
7,8
CVSS
HIGH
Memory Corruption
119
CWE
Product Name: Office
Affected Version From: Microsoft Office 2007
Affected Version To: Microsoft Office 2010
Patch Exists: YES
Related CWE: N/A
CPE: a:microsoft:office:2007
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2012
Microsoft Office 2007/2010 Memory Corruption Vulnerability
The crash is caused by a 1 bit delta from the original file at offset 0x31B. OffViz identified this offset as WordBinaryDocuments[1].WordBinaryDocument[0].WordFIB.FIBTable97.fcPlcfFldMom with an original value of 0x000072C6 and a fuzzed value of 0x00007AC6.
Mitigation:
Disable Microsoft Office File Validation Add-In and enable Application Verifier for testing and reproduction.