>> Microsoft Office Multiple Code Execution Vulnerabilities (MS08-026)
Title : Microsoft Office Multiple Code Execution Vulnerabilities (MS08-026) VUPEN ID : VUPEN/ADV-2008-1504 CVE ID : CVE-2008-1091 - CVE-2008-1434
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-05-13
Technical Description
Two vulnerabilities have been identified in Microsoft Office, which could be exploited by attackers to cause a denial of service or take complete control of an affected system.
The first issue is caused by a memory calculation error when processing a malformed string in a specially crafted .rtf file, which could be exploited by attackers to execute arbitrary code by tricking a user into opening a specially crafted document.
The second vulnerability is caused by a memory corruption error when processing CSS values in a specially crafted Word file, which could be exploited by attackers to execute arbitrary code by tricking a user into opening a specially crafted document.