Executive Summary



This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.
Summary
Title Vulnerabilities in Microsoft Office Graphics Filters Could Allow for Remote Code Execution (968095)
Informations
Name MS10-105 First vendor Publication 2010-12-14
Vendor Microsoft Last vendor Modification 2010-12-15
Severity (Vendor) Important Revision 1.1

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C)
Cvss Base Score 9.3 Attack Range Network
Cvss Impact Score 10 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Revision Note: V1.1 (December 15, 2010): Clarified that customers of Microsoft Office XP and Microsoft Office 2003 need to apply the update in MS10-087 in order to be protected from the vulnerabilities described in this bulletin (MS10-105).Summary: This security update resolves seven privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user viewed a specially crafted image file using Microsoft Office. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Original Source

Url : http://www.microsoft.com/technet/security/bulletin/MS10-105.mspx

CWE : Common Weakness Enumeration

% Id Name
86 % CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer
14 % CWE-189 Numeric Errors (CWE/SANS Top 25)

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:11827
 
Oval ID: oval:org.mitre.oval:def:11827
Title: TIFF Image Converter Heap Overflow Vulnerability
Description: Heap-based buffer overflow in the TIFF image converter in the graphics filters in Microsoft Office XP SP3, Office Converter Pack, and Works 9 allows remote attackers to execute arbitrary code via a crafted TIFF image in an Office document, aka "TIFF Image Converter Heap Overflow Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2010-3947
Version: 11
Platform(s): Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Vista
Microsoft Windows 7
Microsoft Windows Server 2008
Product(s): Microsoft Office 2002
Microsoft Office Converter Pack
Microsoft Works 9
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:11967
 
Oval ID: oval:org.mitre.oval:def:11967
Title: PICT Image Converter Integer Overflow Vulnerability
Description: Integer overflow in the PICT image converter in the graphics filters in Microsoft Office XP SP3, Office 2003 SP3, and Office Converter Pack allows remote attackers to execute arbitrary code via a crafted PICT image in an Office document, aka "PICT Image Converter Integer Overflow Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2010-3946
Version: 11
Platform(s): Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Vista
Microsoft Windows 7
Microsoft Windows Server 2008
Product(s): Microsoft Office 2002
Microsoft Office 2003
Microsoft Office Converter Pack
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:12150
 
Oval ID: oval:org.mitre.oval:def:12150
Title: FlashPix Image Converter Heap Corruption Vulnerability
Description: The FlashPix image converter in the graphics filters in Microsoft Office XP SP3 and Office Converter Pack allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted FlashPix image in an Office document, aka "FlashPix Image Converter Heap Corruption Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2010-3952
Version: 11
Platform(s): Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Vista
Microsoft Windows 7
Microsoft Windows Server 2008
Product(s): Microsoft Office 2002
Microsoft Office Converter Pack
Microsoft Works 9
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:12249
 
Oval ID: oval:org.mitre.oval:def:12249
Title: CGM Image Converter Buffer Overrun Vulnerability
Description: Buffer overflow in the CGM image converter in the graphics filters in Microsoft Office XP SP3, Office 2003 SP3, and Office Converter Pack allows remote attackers to execute arbitrary code via a crafted CGM image in an Office document, aka "CGM Image Converter Buffer Overrun Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2010-3945
Version: 11
Platform(s): Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Vista
Microsoft Windows 7
Microsoft Windows Server 2008
Product(s): Microsoft Office 2002
Microsoft Office 2003
Microsoft Office Converter Pack
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:12289
 
Oval ID: oval:org.mitre.oval:def:12289
Title: TIFF Image Converter Memory Corruption Vulnerability
Description: The TIFF image converter in the graphics filters in Microsoft Office XP SP3, Office Converter Pack, and Works 9 does not properly convert data, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted TIFF image in an Office document, aka "TIFF Image Converter Memory Corruption Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2010-3950
Version: 11
Platform(s): Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Vista
Microsoft Windows 7
Microsoft Windows Server 2008
Product(s): Microsoft Office 2002
Microsoft Office Converter Pack
Microsoft Works 9
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:12350
 
Oval ID: oval:org.mitre.oval:def:12350
Title: FlashPix Image Converter Buffer Overflow Vulnerability
Description: Buffer overflow in the FlashPix image converter in the graphics filters in Microsoft Office XP SP3 and Office Converter Pack allows remote attackers to execute arbitrary code via a crafted FlashPix image in an Office document, aka "FlashPix Image Converter Buffer Overflow Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2010-3951
Version: 11
Platform(s): Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Vista
Microsoft Windows 7
Microsoft Windows Server 2008
Product(s): Microsoft Office 2002
Microsoft Office Converter Pack
Microsoft Works 9
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:12387
 
Oval ID: oval:org.mitre.oval:def:12387
Title: TIFF Image Converter Buffer Overflow Vulnerability
Description: Buffer overflow in the TIFF image converter in the graphics filters in Microsoft Office XP SP3 and Office Converter Pack allows remote attackers to execute arbitrary code via a crafted TIFF image in an Office document, aka "TIFF Image Converter Buffer Overflow Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2010-3949
Version: 11
Platform(s): Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Vista
Microsoft Windows 7
Microsoft Windows Server 2008
Product(s): Microsoft Office 2002
Microsoft Office Converter Pack
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 2
Application 1
Application 1

SAINT Exploits

Description Link
Microsoft Office FlashPix Image Converter Dictionary property buffer overflow More info here

OpenVAS Exploits

Date Description
2010-12-15 Name : Microsoft Office Graphics Filters Remote Code Execution Vulnerabilities (968095)
File : nvt/secpod_ms10-105.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
69809 Microsoft Office FlashPix Image Converter Tile Data Handling Heap Corruption

A memory corruption flaw exists in Microsoft Office. The program fails to sanitize user-supplied input when parsing FlashPix image files, resulting in memory corruption. With a specially crafted FlashPix image file, a context-dependent attacker can execute arbitrary code.
69808 Microsoft Office FlashPix Image Converter Picture Set Processing Overflow

Microsoft Office is prone to an overflow condition. The program improperly parses data in FlashPix image files, resulting in a buffer overflow. With a specially crafted FlashPix image, a context-dependent attacker can potentially execute arbitrary code.
69807 Microsoft Office Document Imaging Endian Conversion TIFF Image Handling Memor...

A memory corruption flaw exists in Microsoft Office. The TIFF Import/Export Graphic Filter fails to sanitize user-supplied input when converting the endianness of certain data resulting in memory corruption. With a specially crafted TIFF image, a context-dependent attacker can execute arbitrary code.
69806 Microsoft Office TIFF Image Converter Endian Conversion Buffer Overflow

Microsoft Office is prone to an overflow condition. The TIFF Import/Export Graphic Filter, after having encountered a specific error, fails to properly sanitize user-supplied input resulting in a heap-based buffer overflow. With a specially TIFF image, a context-dependent attacker can potentially execute arbitrary code.
69805 Microsoft Office TIFF Import/Export Graphic Filter Converter Multiple Overflows

Microsoft Office is prone to an overflow condition. The TIFF Import/Export Graphic Filter fails to properly sanitize user-supplied input resulting in a heap-based buffer overflow. With a specially TIFF image, a context-dependent attacker can potentially execute arbitrary code.
69804 Microsoft Office PICT Image Converter Overflow

Microsoft Office is prone to an overflow condition. The PICT import filter suffers from an integer truncation error resulting in a heap-based overflow. With a specially crafted PICT image, a context-dependent attacker can potentially execute arbitrary code.
69803 Microsoft Office CGM Image Converter Overflow

Microsoft Office is prone to an overflow condition. The CGM Image Converter's filter fails to properly sanitize user-supplied input resulting in a buffer overflow. With a specially crafted CGM image file, a context-dependent attacker can potentially execute arbitrary code.

Information Assurance Vulnerability Management (IAVM)

Date Description
2010-12-16 IAVM : 2010-A-0170 - Multiple Vulnerabilities in Microsoft Office
Severity : Category II - VMSKEY : V0025855

Snort® IPS/IDS

Date Description
2019-09-19 Microsoft Office TIFF filter buffer overflow attempt
RuleID : 51091 - Revision : 1 - Type : FILE-OFFICE
2019-09-19 Microsoft Office TIFF filter buffer overflow attempt
RuleID : 51090 - Revision : 1 - Type : FILE-OFFICE
2019-09-19 Microsoft Office TIFF filter buffer overflow attempt
RuleID : 51089 - Revision : 1 - Type : FILE-OFFICE
2019-09-19 Microsoft Office TIFF filter buffer overflow attempt
RuleID : 51088 - Revision : 1 - Type : FILE-OFFICE
2014-11-16 Microsoft Office .CGM file cell array heap overflow attempt
RuleID : 32064 - Revision : 4 - Type : FILE-OFFICE
2014-11-16 Microsoft Office .CGM file cell array heap overflow attempt
RuleID : 32063 - Revision : 3 - Type : FILE-OFFICE
2014-11-16 Microsoft Office .CGM file cell array heap overflow attempt
RuleID : 32062 - Revision : 4 - Type : FILE-OFFICE
2014-01-10 Microsoft Office .CGM file cell array heap overflow attempt
RuleID : 24823 - Revision : 4 - Type : FILE-OFFICE
2014-01-10 Microsoft Office TIFF filter buffer overflow attempt
RuleID : 24558 - Revision : 5 - Type : FILE-OFFICE
2014-01-10 Microsoft Office TIFF filter buffer overflow attempt
RuleID : 24557 - Revision : 5 - Type : FILE-OFFICE
2014-01-10 Microsoft Office TIFF filter buffer overflow attempt
RuleID : 24556 - Revision : 6 - Type : FILE-OFFICE
2014-01-10 Microsoft Kodak Imaging large offset malformed tiff - big-endian
RuleID : 23561 - Revision : 8 - Type : FILE-IMAGE
2014-01-10 Microsoft Office TIFF filter buffer overflow attempt
RuleID : 23530 - Revision : 8 - Type : FILE-OFFICE
2014-01-10 Microsoft Office TIFF filter buffer overflow attempt
RuleID : 23529 - Revision : 5 - Type : FILE-OFFICE
2014-01-10 Microsoft Office PICT graphics converter memory corruption attempt
RuleID : 23528 - Revision : 4 - Type : FILE-OFFICE
2014-01-10 Microsoft Office .CGM file cell array heap overflow attempt
RuleID : 23527 - Revision : 5 - Type : FILE-OFFICE
2014-01-10 Microsoft Office .CGM file cell array heap overflow attempt
RuleID : 23526 - Revision : 5 - Type : FILE-OFFICE
2014-01-10 Microsoft Office TIFF filter buffer overflow attempt
RuleID : 23386 - Revision : 5 - Type : FILE-OFFICE
2014-01-10 Microsoft Office TIFF filter remote code execution attempt
RuleID : 19316 - Revision : 8 - Type : FILE-OFFICE
2014-01-10 Microsoft Office .CGM file cell array heap overflow attempt
RuleID : 19156 - Revision : 14 - Type : FILE-OFFICE
2014-01-10 Microsoft Windows Flashpix graphics filter fpx32.flt remote code execution at...
RuleID : 18237 - Revision : 15 - Type : FILE-IMAGE
2014-01-10 Microsoft Office TIFFIM32.FLT filter memory corruption attempt
RuleID : 18236 - Revision : 14 - Type : FILE-OFFICE
2014-01-10 Microsoft Office PICT graphics converter memory corruption attempt
RuleID : 18235 - Revision : 14 - Type : FILE-OFFICE
2014-01-10 Microsoft FlashPix tile length overflow attempt
RuleID : 18229 - Revision : 15 - Type : FILE-IMAGE
2014-01-10 Microsoft Office TIFF filter buffer overflow attempt
RuleID : 18201 - Revision : 16 - Type : FILE-OFFICE
2014-01-10 Microsoft Office .CGM file cell array heap overflow attempt
RuleID : 18200 - Revision : 16 - Type : FILE-OFFICE
2014-01-10 Microsoft Kodak Imaging large offset malformed tiff - big-endian
RuleID : 17232 - Revision : 21 - Type : FILE-IMAGE

Nessus® Vulnerability Scanner

Date Description
2010-12-15 Name : Arbitrary code can be executed on the remote host through the Microsoft Offic...
File : smb_nt_ms10-105.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
Date Informations
2014-11-16 21:25:22
  • Multiple Updates
2014-02-17 11:46:49
  • Multiple Updates
2014-01-19 21:30:35
  • Multiple Updates
2013-11-11 12:41:20
  • Multiple Updates
2013-05-11 00:49:45
  • Multiple Updates