vendor:
Office 2007
by:
Google Security Research
8,8
CVSS
HIGH
Access Violation
119
CWE
Product Name: Office 2007
Affected Version From: Microsoft Office 2007
Affected Version To: Microsoft Office 2007
Patch Exists: YES
Related CWE: N/A
CPE: a:microsoft:office:2007
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows Server 2003 and Windows 7
2009
Microsoft Office 2007 Access Violation
An access violation was observed in Microsoft Office 2007 (Word document). The crash occurs due to an invalid read dereference of a bad object pointer. If the word value read is controlled and set to a value other than 0xFFFF, then a controlled value is used as an indirect call target (at 328A1DD4 in MSO.dll).
Mitigation:
Update to the latest version of Microsoft Office 2007