|
|
>> Microsoft Office OneNote URL Code Execution (MS08-055)
|
Title : Microsoft Office OneNote URL Code Execution (MS08-055) Advisory ID : VUPEN/ADV-2008-2523 CVE ID : CVE-2008-3007 CWE ID : CWE-20
Rated as : Critical 
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-09-09
|
|
A vulnerability has been identified in Microsoft Office, which could be exploited by remote attackers to take complete control of an input validation error when a specially crafted uniform resource locator is passed to open a specially crafted OneNote file, which could be exploited by attackers to crash an affected application or execute arbitrary code by tricking a user into clicking on specially crafted URL using the OneNote protocol handler (onenote://).
Credits
Vulnerability reported by Brett Moore (Insomnia Security).
ChangeLog
2008-09-09 : Initial release
Vulnerability Management
Subscribe to VUPEN Security VNS and receive real-time e-mail and SMS alerts when new vulnerabilities, exploits, or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form or by email to updates@vupen.com. | |
|