Executive Summary
Summary | |
---|---|
Title | Vulnerabilities in Microsoft Office Graphics Filters Could Allow for Remote Code Execution (968095) |
Informations | |||
---|---|---|---|
Name | MS10-105 | First vendor Publication | 2010-12-14 |
Vendor | Microsoft | Last vendor Modification | 2010-12-15 |
Severity (Vendor) | Important | Revision | 1.1 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Revision Note: V1.1 (December 15, 2010): Clarified that customers of Microsoft Office XP and Microsoft Office 2003 need to apply the update in MS10-087 in order to be protected from the vulnerabilities described in this bulletin (MS10-105).Summary: This security update resolves seven privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user viewed a specially crafted image file using Microsoft Office. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. |
Original Source
Url : http://www.microsoft.com/technet/security/bulletin/MS10-105.mspx |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
86 % | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
14 % | CWE-189 | Numeric Errors (CWE/SANS Top 25) |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:11827 | |||
Oval ID: | oval:org.mitre.oval:def:11827 | ||
Title: | TIFF Image Converter Heap Overflow Vulnerability | ||
Description: | Heap-based buffer overflow in the TIFF image converter in the graphics filters in Microsoft Office XP SP3, Office Converter Pack, and Works 9 allows remote attackers to execute arbitrary code via a crafted TIFF image in an Office document, aka "TIFF Image Converter Heap Overflow Vulnerability." | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2010-3947 | Version: | 11 |
Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista Microsoft Windows 7 Microsoft Windows Server 2008 | Product(s): | Microsoft Office 2002 Microsoft Office Converter Pack Microsoft Works 9 |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:11967 | |||
Oval ID: | oval:org.mitre.oval:def:11967 | ||
Title: | PICT Image Converter Integer Overflow Vulnerability | ||
Description: | Integer overflow in the PICT image converter in the graphics filters in Microsoft Office XP SP3, Office 2003 SP3, and Office Converter Pack allows remote attackers to execute arbitrary code via a crafted PICT image in an Office document, aka "PICT Image Converter Integer Overflow Vulnerability." | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2010-3946 | Version: | 11 |
Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista Microsoft Windows 7 Microsoft Windows Server 2008 | Product(s): | Microsoft Office 2002 Microsoft Office 2003 Microsoft Office Converter Pack |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:12150 | |||
Oval ID: | oval:org.mitre.oval:def:12150 | ||
Title: | FlashPix Image Converter Heap Corruption Vulnerability | ||
Description: | The FlashPix image converter in the graphics filters in Microsoft Office XP SP3 and Office Converter Pack allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted FlashPix image in an Office document, aka "FlashPix Image Converter Heap Corruption Vulnerability." | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2010-3952 | Version: | 11 |
Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista Microsoft Windows 7 Microsoft Windows Server 2008 | Product(s): | Microsoft Office 2002 Microsoft Office Converter Pack Microsoft Works 9 |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:12249 | |||
Oval ID: | oval:org.mitre.oval:def:12249 | ||
Title: | CGM Image Converter Buffer Overrun Vulnerability | ||
Description: | Buffer overflow in the CGM image converter in the graphics filters in Microsoft Office XP SP3, Office 2003 SP3, and Office Converter Pack allows remote attackers to execute arbitrary code via a crafted CGM image in an Office document, aka "CGM Image Converter Buffer Overrun Vulnerability." | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2010-3945 | Version: | 11 |
Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista Microsoft Windows 7 Microsoft Windows Server 2008 | Product(s): | Microsoft Office 2002 Microsoft Office 2003 Microsoft Office Converter Pack |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:12289 | |||
Oval ID: | oval:org.mitre.oval:def:12289 | ||
Title: | TIFF Image Converter Memory Corruption Vulnerability | ||
Description: | The TIFF image converter in the graphics filters in Microsoft Office XP SP3, Office Converter Pack, and Works 9 does not properly convert data, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted TIFF image in an Office document, aka "TIFF Image Converter Memory Corruption Vulnerability." | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2010-3950 | Version: | 11 |
Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista Microsoft Windows 7 Microsoft Windows Server 2008 | Product(s): | Microsoft Office 2002 Microsoft Office Converter Pack Microsoft Works 9 |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:12350 | |||
Oval ID: | oval:org.mitre.oval:def:12350 | ||
Title: | FlashPix Image Converter Buffer Overflow Vulnerability | ||
Description: | Buffer overflow in the FlashPix image converter in the graphics filters in Microsoft Office XP SP3 and Office Converter Pack allows remote attackers to execute arbitrary code via a crafted FlashPix image in an Office document, aka "FlashPix Image Converter Buffer Overflow Vulnerability." | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2010-3951 | Version: | 11 |
Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista Microsoft Windows 7 Microsoft Windows Server 2008 | Product(s): | Microsoft Office 2002 Microsoft Office Converter Pack Microsoft Works 9 |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:12387 | |||
Oval ID: | oval:org.mitre.oval:def:12387 | ||
Title: | TIFF Image Converter Buffer Overflow Vulnerability | ||
Description: | Buffer overflow in the TIFF image converter in the graphics filters in Microsoft Office XP SP3 and Office Converter Pack allows remote attackers to execute arbitrary code via a crafted TIFF image in an Office document, aka "TIFF Image Converter Buffer Overflow Vulnerability." | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2010-3949 | Version: | 11 |
Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista Microsoft Windows 7 Microsoft Windows Server 2008 | Product(s): | Microsoft Office 2002 Microsoft Office Converter Pack |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 2 | |
Application | 1 | |
Application | 1 |
SAINT Exploits
Description | Link |
---|---|
Microsoft Office FlashPix Image Converter Dictionary property buffer overflow | More info here |
OpenVAS Exploits
Date | Description |
---|---|
2010-12-15 | Name : Microsoft Office Graphics Filters Remote Code Execution Vulnerabilities (968095) File : nvt/secpod_ms10-105.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
69809 | Microsoft Office FlashPix Image Converter Tile Data Handling Heap Corruption A memory corruption flaw exists in Microsoft Office. The program fails to sanitize user-supplied input when parsing FlashPix image files, resulting in memory corruption. With a specially crafted FlashPix image file, a context-dependent attacker can execute arbitrary code. |
69808 | Microsoft Office FlashPix Image Converter Picture Set Processing Overflow Microsoft Office is prone to an overflow condition. The program improperly parses data in FlashPix image files, resulting in a buffer overflow. With a specially crafted FlashPix image, a context-dependent attacker can potentially execute arbitrary code. |
69807 | Microsoft Office Document Imaging Endian Conversion TIFF Image Handling Memor... A memory corruption flaw exists in Microsoft Office. The TIFF Import/Export Graphic Filter fails to sanitize user-supplied input when converting the endianness of certain data resulting in memory corruption. With a specially crafted TIFF image, a context-dependent attacker can execute arbitrary code. |
69806 | Microsoft Office TIFF Image Converter Endian Conversion Buffer Overflow Microsoft Office is prone to an overflow condition. The TIFF Import/Export Graphic Filter, after having encountered a specific error, fails to properly sanitize user-supplied input resulting in a heap-based buffer overflow. With a specially TIFF image, a context-dependent attacker can potentially execute arbitrary code. |
69805 | Microsoft Office TIFF Import/Export Graphic Filter Converter Multiple Overflows Microsoft Office is prone to an overflow condition. The TIFF Import/Export Graphic Filter fails to properly sanitize user-supplied input resulting in a heap-based buffer overflow. With a specially TIFF image, a context-dependent attacker can potentially execute arbitrary code. |
69804 | Microsoft Office PICT Image Converter Overflow Microsoft Office is prone to an overflow condition. The PICT import filter suffers from an integer truncation error resulting in a heap-based overflow. With a specially crafted PICT image, a context-dependent attacker can potentially execute arbitrary code. |
69803 | Microsoft Office CGM Image Converter Overflow Microsoft Office is prone to an overflow condition. The CGM Image Converter's filter fails to properly sanitize user-supplied input resulting in a buffer overflow. With a specially crafted CGM image file, a context-dependent attacker can potentially execute arbitrary code. |
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2010-12-16 | IAVM : 2010-A-0170 - Multiple Vulnerabilities in Microsoft Office Severity : Category II - VMSKEY : V0025855 |
Snort® IPS/IDS
Date | Description |
---|---|
2019-09-19 | Microsoft Office TIFF filter buffer overflow attempt RuleID : 51091 - Revision : 1 - Type : FILE-OFFICE |
2019-09-19 | Microsoft Office TIFF filter buffer overflow attempt RuleID : 51090 - Revision : 1 - Type : FILE-OFFICE |
2019-09-19 | Microsoft Office TIFF filter buffer overflow attempt RuleID : 51089 - Revision : 1 - Type : FILE-OFFICE |
2019-09-19 | Microsoft Office TIFF filter buffer overflow attempt RuleID : 51088 - Revision : 1 - Type : FILE-OFFICE |
2014-11-16 | Microsoft Office .CGM file cell array heap overflow attempt RuleID : 32064 - Revision : 4 - Type : FILE-OFFICE |
2014-11-16 | Microsoft Office .CGM file cell array heap overflow attempt RuleID : 32063 - Revision : 3 - Type : FILE-OFFICE |
2014-11-16 | Microsoft Office .CGM file cell array heap overflow attempt RuleID : 32062 - Revision : 4 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Office .CGM file cell array heap overflow attempt RuleID : 24823 - Revision : 4 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Office TIFF filter buffer overflow attempt RuleID : 24558 - Revision : 5 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Office TIFF filter buffer overflow attempt RuleID : 24557 - Revision : 5 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Office TIFF filter buffer overflow attempt RuleID : 24556 - Revision : 6 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Kodak Imaging large offset malformed tiff - big-endian RuleID : 23561 - Revision : 8 - Type : FILE-IMAGE |
2014-01-10 | Microsoft Office TIFF filter buffer overflow attempt RuleID : 23530 - Revision : 8 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Office TIFF filter buffer overflow attempt RuleID : 23529 - Revision : 5 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Office PICT graphics converter memory corruption attempt RuleID : 23528 - Revision : 4 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Office .CGM file cell array heap overflow attempt RuleID : 23527 - Revision : 5 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Office .CGM file cell array heap overflow attempt RuleID : 23526 - Revision : 5 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Office TIFF filter buffer overflow attempt RuleID : 23386 - Revision : 5 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Office TIFF filter remote code execution attempt RuleID : 19316 - Revision : 8 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Office .CGM file cell array heap overflow attempt RuleID : 19156 - Revision : 14 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Windows Flashpix graphics filter fpx32.flt remote code execution at... RuleID : 18237 - Revision : 15 - Type : FILE-IMAGE |
2014-01-10 | Microsoft Office TIFFIM32.FLT filter memory corruption attempt RuleID : 18236 - Revision : 14 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Office PICT graphics converter memory corruption attempt RuleID : 18235 - Revision : 14 - Type : FILE-OFFICE |
2014-01-10 | Microsoft FlashPix tile length overflow attempt RuleID : 18229 - Revision : 15 - Type : FILE-IMAGE |
2014-01-10 | Microsoft Office TIFF filter buffer overflow attempt RuleID : 18201 - Revision : 16 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Office .CGM file cell array heap overflow attempt RuleID : 18200 - Revision : 16 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Kodak Imaging large offset malformed tiff - big-endian RuleID : 17232 - Revision : 21 - Type : FILE-IMAGE |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2010-12-15 | Name : Arbitrary code can be executed on the remote host through the Microsoft Offic... File : smb_nt_ms10-105.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-11-16 21:25:22 |
|
2014-02-17 11:46:49 |
|
2014-01-19 21:30:35 |
|
2013-11-11 12:41:20 |
|
2013-05-11 00:49:45 |
|