|
|
Microsoft Office Malformed Drawing Object Remote Code Execution Vulnerability
|
Bugtraq ID:
|
23826
|
|
Class:
|
Input Validation Error
|
|
CVE:
|
CVE-2007-1747
CVE-2008-0113
|
|
Remote:
|
Yes
|
|
Local:
|
No
|
|
Published:
|
May 08 2007 12:00AM
|
|
Updated:
|
May 01 2008 01:56PM
|
|
Credit:
|
The vendor credits Arnaud Dovi, working with Zero Day Initiative, for discovering this issue.
|
|
Vulnerable:
|
Microsoft Office XP SP3
+
Microsoft Excel 2002 SP3
+
Microsoft Excel 2002 SP3
+
Microsoft FrontPage 2002 SP3
+
Microsoft FrontPage 2002 SP3
+
Microsoft Outlook 2002 SP3
+
Microsoft Outlook 2002 SP3
+
Microsoft PowerPoint 2002 SP3
+
Microsoft PowerPoint 2002 SP3
+
Microsoft Publisher 2002 SP3
+
Microsoft Publisher 2002 SP3
Microsoft Office XP SP2
-
Microsoft Windows 2000 Professional SP3
-
Microsoft Windows 2000 Professional SP2
-
Microsoft Windows 2000 Professional SP1
-
Microsoft Windows 2000 Professional
-
Microsoft Windows 98
-
Microsoft Windows 98SE
-
Microsoft Windows ME
-
Microsoft Windows NT Workstation 4.0 SP6a
-
Microsoft Windows NT Workstation 4.0 SP6
-
Microsoft Windows NT Workstation 4.0 SP5
-
Microsoft Windows NT Workstation 4.0 SP4
-
Microsoft Windows NT Workstation 4.0 SP3
-
Microsoft Windows NT Workstation 4.0 SP2
-
Microsoft Windows NT Workstation 4.0 SP1
-
Microsoft Windows NT Workstation 4.0
-
Microsoft Windows XP Home SP1
-
Microsoft Windows XP Home
-
Microsoft Windows XP Professional SP1
-
Microsoft Windows XP Professional
Microsoft Office XP SP1
-
Microsoft Windows 2000 Professional SP2
-
Microsoft Windows 2000 Professional SP1
-
Microsoft Windows 2000 Professional
-
Microsoft Windows 98
-
Microsoft Windows ME
-
Microsoft Windows NT Workstation 4.0 SP6a
-
Microsoft Windows NT Workstation 4.0 SP6
-
Microsoft Windows NT Workstation 4.0 SP5
-
Microsoft Windows NT Workstation 4.0 SP4
-
Microsoft Windows NT Workstation 4.0 SP3
-
Microsoft Windows NT Workstation 4.0 SP2
-
Microsoft Windows NT Workstation 4.0 SP1
-
Microsoft Windows NT Workstation 4.0
-
Microsoft Windows XP Home
-
Microsoft Windows XP Professional
Microsoft Office XP
-
Microsoft Windows 2000 Professional SP2
-
Microsoft Windows 2000 Professional SP1
-
Microsoft Windows 2000 Professional
-
Microsoft Windows 98
-
Microsoft Windows ME
-
Microsoft Windows NT Workstation 4.0 SP6a
-
Microsoft Windows NT Workstation 4.0 SP6
-
Microsoft Windows NT Workstation 4.0 SP5
-
Microsoft Windows NT Workstation 4.0 SP4
-
Microsoft Windows NT Workstation 4.0 SP3
-
Microsoft Windows NT Workstation 4.0 SP2
-
Microsoft Windows NT Workstation 4.0 SP1
-
Microsoft Windows NT Workstation 4.0
-
Microsoft Windows XP Home
-
Microsoft Windows XP Professional
Microsoft Office Compatibility Pack 2007 0
Microsoft Office 2007 0
+
Microsoft Access 2007 0
+
Microsoft Access 2007 0
+
Microsoft Excel 2003
+
Microsoft Excel 2007 0
+
Microsoft Excel 2007 0
+
Microsoft FrontPage 2003
+
Microsoft Groove 2007 0
+
Microsoft Groove 2007 0
+
Microsoft InfoPath 2003
+
Microsoft InfoPath 2007 0
+
Microsoft InfoPath 2007 0
+
Microsoft Office Communicator 2007 0
+
Microsoft Office Communicator 2007 0
+
Microsoft OneNote 2003 0
+
Microsoft Outlook 2003 0
+
Microsoft Outlook 2007 0
+
Microsoft Outlook 2007 0
+
Microsoft PowerPoint 2003 0
+
Microsoft PowerPoint 2007 0
+
Microsoft PowerPoint 2007 0
+
Microsoft Project Professional 2007 0
+
Microsoft Project Professional 2007 0
+
Microsoft Project Standard 2007 0
+
Microsoft Project Standard 2007 0
+
Microsoft Publisher 2003
+
Microsoft Publisher 2007 0
+
Microsoft Publisher 2007 0
+
Microsoft SharePoint Designer 2007 0
+
Microsoft SharePoint Designer 2007 0
+
Microsoft Visio Professional 2007 0
+
Microsoft Visio Professional 2007 0
+
Microsoft Visio Standard 2007 0
+
Microsoft Visio Standard 2007 0
Microsoft Office 2004 for Mac 0
Microsoft Office 2003 SP2
Microsoft Office 2003 SP1
Microsoft Office 2003 0
+
Microsoft Excel 2003
+
Microsoft FrontPage 2003
+
Microsoft InfoPath 2003
+
Microsoft OneNote 2003 0
+
Microsoft Outlook 2003 0
+
Microsoft PowerPoint 2003 0
+
Microsoft Publisher 2003
Microsoft Office 2000 SP3
-
Microsoft Windows 2000 Professional SP3
-
Microsoft Windows 2000 Professional SP2
-
Microsoft Windows 2000 Professional SP1
-
Microsoft Windows 2000 Professional
-
Microsoft Windows 98
-
Microsoft Windows 98SE
-
Microsoft Windows ME
-
Microsoft Windows NT Workstation 4.0 SP6a
-
Microsoft Windows NT Workstation 4.0 SP6
-
Microsoft Windows NT Workstation 4.0 SP5
-
Microsoft Windows NT Workstation 4.0 SP4
-
Microsoft Windows NT Workstation 4.0 SP3
-
Microsoft Windows NT Workstation 4.0 SP2
-
Microsoft Windows NT Workstation 4.0 SP1
-
Microsoft Windows NT Workstation 4.0
-
Microsoft Windows XP Home SP1
-
Microsoft Windows XP Home
-
Microsoft Windows XP Professional SP1
-
Microsoft Windows XP Professional
Microsoft Office 2000 SP2
-
Microsoft Windows 2000 Professional SP2
-
Microsoft Windows 2000 Professional SP1
-
Microsoft Windows 2000 Professional
-
Microsoft Windows ME
-
Microsoft Windows NT Workstation 4.0 SP6a
-
Microsoft Windows NT Workstation 4.0 SP6
-
Microsoft Windows NT Workstation 4.0 SP5
-
Microsoft Windows NT Workstation 4.0 SP4
-
Microsoft Windows NT Workstation 4.0 SP3
-
Microsoft Windows NT Workstation 4.0 SP2
-
Microsoft Windows NT Workstation 4.0 SP1
-
Microsoft Windows NT Workstation 4.0
-
Microsoft Windows XP Home
-
Microsoft Windows XP Professional
Microsoft Office 2000 SP1
-
Microsoft Windows 2000 Professional SP2
-
Microsoft Windows 2000 Professional SP1
-
Microsoft Windows 2000 Professional
-
Microsoft Windows ME
-
Microsoft Windows NT Workstation 4.0 SP6a
-
Microsoft Windows NT Workstation 4.0 SP6
-
Microsoft Windows NT Workstation 4.0 SP5
-
Microsoft Windows NT Workstation 4.0 SP4
-
Microsoft Windows NT Workstation 4.0 SP3
-
Microsoft Windows NT Workstation 4.0 SP2
-
Microsoft Windows NT Workstation 4.0 SP1
-
Microsoft Windows NT Workstation 4.0
-
Microsoft Windows XP Home
-
Microsoft Windows XP Professional
Microsoft Office 2000
-
Microsoft Windows 2000 Professional SP2
-
Microsoft Windows 2000 Professional SP1
-
Microsoft Windows 2000 Professional
-
Microsoft Windows 95
-
Microsoft Windows 98
-
Microsoft Windows ME
-
Microsoft Windows NT Workstation 4.0 SP6a
-
Microsoft Windows NT Workstation 4.0 SP6
-
Microsoft Windows NT Workstation 4.0 SP5
-
Microsoft Windows NT Workstation 4.0 SP4
-
Microsoft Windows NT Workstation 4.0 SP3
-
Microsoft Windows NT Workstation 4.0 SP2
-
Microsoft Windows NT Workstation 4.0 SP1
-
Microsoft Windows NT Workstation 4.0
-
Microsoft Windows XP Home
-
Microsoft Windows XP Professional
Microsoft Internet Explorer for Unix SP2
Microsoft Excel Viewer 2003 0
+
Microsoft Office 2003 SP1
Avaya Messaging Application Server 0
Avaya CIE 1.0
|
|
|
|
Not Vulnerable:
|
|
|

|