
December 29th, 2010, 05:21 PM
|
 |
Global Moderator
|
|
Join Date: Jul 2003
Location: Texas
Posts: 46,210
|
|
Targeted attacks against recently addressed Microsoft Office vulnerability (CVE-2010-
Quote:
mmpc
29 Dec 2010 12:10 PM
Last November, Microsoft released security bulletin MS10-087, which addresses a number of critical vulnerabilities in how Microsoft Office parses various office file formats. One of them is CVE-2010-3333, "RTF Stack Buffer Overflow Vulnerability," which could lead to remote code execution via specially crafted RTF data. A few days before Christmas, we received a new sample (sha1: cc47a73118c51b0d32fd88d48863afb1af7b2578 ) that reliably exploits this vulnerability and is able to execute malicious shellcode which downloads other malware.
|
Microsoft
|