Kod programskog paketa Microsoft Visio uočen je novi sigurnosni propust koji zlonamjernim korisnicima omogućuje umetanje i pokretanje vlastitog programskog koda.
Paket:
Microsoft Visio 2003
Operacijski sustavi:
Microsoft Windows XP, Microsoft Windows Server 2003, Microsoft Windows Vista, Microsoft Windows Server 2008, Microsoft Windows 7
Problem:
pogreška u programskoj komponenti
Iskorištavanje:
udaljeno
Posljedica:
proizvoljno izvršavanje programskog koda
Rješenje:
zaobilazno rješenje (workaround)
Izvorni ID preporuke:
SA45077
Izvor:
Secunia
Problem:
Uočen nedostatak javlja se zbog nesigurnog načina učitavanja programskih biblioteka (mfc71enu.dll i mfc71loc.dll).
Posljedica:
Udaljeni napadači mogu iskoristiti nedostatak za izvršavanje zlonamjernog programskog koda navođenjem korisnika na otvaranje posebno oblikovanih ".vss" datoteka.
Rješenje:
Zakrpa za ovaj sigurnosni nedostatak trenutno ne postoji. Korisnicima se preporuča da ne otvaraju datoteke iz nepouzdanih izvora.
Secunia Advisory SA45077
Microsoft Visio Insecure Library Loading Vulnerability
Secunia Advisory SA45077
Release Date 2011-07-08
Criticality level Highly criticalHighly critical
Impact System access
Where From remote
Authentication level Available in Customer Area
Report reliability Available in Customer Area
Solution Status Unpatched
Systems affected Available in Customer Area
Approve distribution Available in Customer Area
Remediation status Secunia VIM
Software:
Microsoft Visio 2003
Secunia CVSS Score Available in Customer Area
CVE Reference(s) No CVE references.
Description
A vulnerability has been discovered in Microsoft Visio, which can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to the application loading libraries (e.g. mfc71enu.dll and mfc71loc.dll) in an insecure manner. This can be exploited to load arbitrary libraries by tricking a user into e.g. opening a Microsoft Visio Stencil (".vss") file located on a remote WebDAV or SMB share.
Successful exploitation allows execution of arbitrary code.
The vulnerability is confirmed in version 2003 (11.3216.5606). Other versions may also be affected.
Solution
Do not open untrusted files.
Provided and/or discovered by
Beenu Arora
Original Advisory
http://www.exploit-db.com/exploits/14744/
Posljednje sigurnosne preporuke