vendor:
Microsoft Office 2007
by:
Google Security Research
7,8
CVSS
HIGH
Crash
119
CWE
Product Name: Microsoft Office 2007
Affected Version From: Microsoft Office 2007
Affected Version To: Microsoft Office 2007
Patch Exists: YES
Related CWE: N/A
CPE: microsoft:office:2007
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2014
Microsoft Office 2007 Crash with Microsoft Office File Validation Add-In disabled and Application Verifier enabled
A crash was observed in Microsoft Office 2007 with Microsoft Office File Validation Add-In disabled and Application Verifier enabled. This bug did not reproduce in Office 2010 or 2013. The minimized crashing file shows two one bit deltas from the original file. The first delta at offset 0x1CF7E and the second is at offset 0x3A966. Both of these offset appear to be BIFFRecord lengths.
Mitigation:
Enabling Microsoft Office File Validation Add-In and disabling Application Verifier.