| PROBLEM: | A remote code execution vulnerability exists in the way Microsoft Office handles a specially crafted drawing object. |
| PLATFORM: | Tested Software and Security Update Download Locations: Affected Software: • Microsoft Office 2000 Service Pack 3 • Microsoft Excel 2000 • Microsoft FrontPage 2000 • Microsoft Publisher 2000 • Microsoft Office XP Service Pack 3 • Microsoft Excel 2002 • Microsoft FrontPage 2002 • Microsoft Publisher 2002 • Microsoft Office 2003 Service Pack 2 • Microsoft Excel 2003 • Microsoft FrontPage 2003 • Microsoft Publisher 2003 • Microsoft Excel 2003 Viewer • 2007 Microsoft Office System • Microsoft Office Excel 2007 • Microsoft Office Publisher 2007 • Microsoft Office SharePoint Designer 2007 • Microsoft Expression Web • Microsoft Office 2004 for Mac • Microsoft Office Compatibility Pack • Word, Excel, and PowerPoint 2007 File Formats Non-Affected Software: • Microsoft Works Suites: • Microsoft Works Suite 2004 • Microsoft Works Suite 2005 • Microsoft Works Suite 2006 • Microsoft Office 2000 Service Pack 3 • Microsoft Access 2000 • Microsoft Outlook 2000 • Microsoft PowerPoint 2000 • Microsoft Project 2000 Service Release 1 • Microsoft Word 2000 • Microsoft Office XP Service Pack 3 • Microsoft Access 2002 • Microsoft Outlook 2002 • Microsoft PowerPoint 2002 • Microsoft Project 2002 Service Pack 1 • Microsoft Visio 2002 • Microsoft Word 2002 • Microsoft Office 2003 Service Pack 2: • Microsoft Access 2003 • Microsoft InfoPath 2003 • Microsoft OneNote 2003 • Microsoft Outlook 2003 • Microsoft Project 2003 • Microsoft PowerPoint 2003 • Microsoft PowerPoint 2003 Viewer • Microsoft Visio 2003 • Microsoft Word 2003 • Microsoft Word 2003 Viewer • 2007 Microsoft Office System • Microsoft Office Access 2007 • Microsoft Office PowerPoint 2007 • Microsoft Office Project 2007 • Microsoft Office Visio 2007 • Microsoft Office Word 2007 • Word, Excel, and PowerPoint 2007 File Formats Service Pack 1 |
| DAMAGE: | Could allow remote code execution. |
| SOLUTION: | Upgrade to the appropriate version. |
| VULNERABILITY ASSESSMENT: |
The risk is MEDIUM. Code runs in the context of the user. |
| LINKS: | |
| CIAC BULLETIN: | http://www.ciac.org/ciac/bulletins/r-232.shtml |
| ORIGINAL BULLETIN: | http://www.microsoft.com/technet/security/Bulletin/MS07-025.mspx |
| CVE: | CVE-2007-1747 |
REVISION HISTORY:
05/17/2007 - revised R-232 to reflect changes Microsoft has made in MS07-025 where
they updated the workaround section with the removal of the "Use
Microsoft Word Viewer 2003 to open and view files" workaround.
05/21/2007 - revised R-232 to reflect changes Microsoft has made in MS07-025 where
they updated due to new issues discovered with the security update as
reflected in Microsoft Knowledge Base Article 934873.
03/28/2008 - revised R-232 to reflect changes Microsoft has made in MS07-025 where
they added Microsoft Office Compatibility Pack for Word, Excel, and
PowerPoint 2007 File Formats and Microsoft Office Compatibility Pack
for Word, Excel, and PowerPoint 2007 File Formats Service Pack 1 to
the Affected Software list.
05/01/2008 - revised R-232 to reflect changes Microsoft has made in MS07-025 where
they moved Microsoft Office Compatibility Pack for Word, Excel, and
PowerPoint 2007 File Formats Service Pack 1 from the Affected Software
list to the Non-Affected Software list.
[***** Start Microsoft Security Bulletin MS07-025 (934873) *****]
Version: 2.1
Who Should Read this Document: Customers who use Microsoft Office
Impact of Vulnerability: Remote Code Execution
Maximum Severity Rating: Critical
Recommendation: Customers should apply the update immediately
Security Update Replacement: This bulletin replaces a prior security update. See the Frequently Asked Questions (FAQ) section of this bulletin for details.
Caveats: None
Tested Software and Security Update Download Locations:
Affected Software:
| • | Microsoft Office 2000 Service Pack 3 — Download the update (KB934526)
|
||||||||||
| • | Microsoft Office XP Service Pack 3 — Download the update (KB934705)
|
||||||||||
| • | Microsoft Office 2003 Service Pack 2 — Download the update (KB934180)
|
||||||||||
| • | 2007 Microsoft Office System — Download the update (KB934062)
|
||||||||||
| • | Microsoft Office 2004 for Mac — Download the update (KB936749) |
Non-Affected Software:
| • | Microsoft Works Suites:
|
||||||||||||||||||||
| • | Microsoft Office 2000 Service Pack 3
|
||||||||||||||||||||
| • | Microsoft Office XP Service Pack 3
|
||||||||||||||||||||
| • | Microsoft Office 2003 Service Pack 2:
|
||||||||||||||||||||
| • | 2007 Microsoft Office System
|
The software in this list has been tested to determine whether the versions are affected. Other versions are either past their support life cycle or are not affected. To determine the support life cycle for your product and version, visit the Microsoft Support Lifecycle Web site.