Overview
Microsoft Office Publisher fails to properly validate Publisher documents, which may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system.
Description
Microsoft Publisher is a desktop publishing application that is provided with some versions of Microsoft Office. Microsoft Publisher fails to properly handle malformed publisher (.pub) documents, which can result in an exploitable situation. The vulnerabilities include: Out-of-bounds array indexing, invalid pointer use, and memory corruption. |
Impact
By convincing a user to open a specially crafted Publisher document, a remote, unauthenticated attacker could execute arbitrary code with the privileges of the user running Publisher. |
Solution
Apply an update These issues are addressed in Microsoft Security Bulletin MS11-091. Please also consider the following workarounds: |
Use the Microsoft Enhanced Mitigation Experience Toolkit |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 9 | AV:N/AC:M/Au:N/C:C/I:C/A:P |
Temporal | 7 | E:POC/RL:OF/RC:C |
Environmental | 7 | CDP:ND/TD:ND/CR:ND/IR:ND/AR:ND |
References
- http://technet.microsoft.com/en-us/security/bulletin/ms11-091
- http://www.microsoft.com/download/en/details.aspx?id=1677
- http://blogs.technet.com/b/srd/archive/2009/06/05/understanding-dep-as-a-mitigation-technology-part-1.aspx
- http://blogs.technet.com/b/srd/archive/2009/06/12/understanding-dep-as-a-mitigation-technology-part-2.aspx
- http://blogs.technet.com/b/srd/archive/2010/12/08/on-the-effectiveness-of-dep-and-aslr.aspx
Acknowledgements
This vulnerability was reported by Will Dormann of the CERT/CC.
This document was written by Will Dormann.
Other Information
CVE IDs: | CVE-2011-3410, CVE-2011-3411, CVE-2011-3412 |
Severity Metric: | 6.69 |
Date Public: | 2011-12-13 |
Date First Published: | 2011-12-13 |
Date Last Updated: | 2012-03-28 15:02 UTC |
Document Revision: | 15 |