SecurityFocus Microsoft Newsletter #423

[email protected] Fri, 12 Dec 2008 10:34:13 -0700
Newsgroups gmane.comp.security.news.microsoft
Message-ID <[email protected]>
SecurityFocus Microsoft Newsletter #423
----------------------------------------

This issue is sponsored by Ironkey: The World's Most Secure Flash Drive

IronKey flash dives lock down your most sensitive data using today's most=
 advanced security technology.=20
IronKey uses military-grade AES CBC-mode hardware encryption that cannot =
be disabled by malware or an intruder and provides rugged and waterproof =
protection to safeguard your data.
https://www.ironkey.com/secure-flash-drive1a?cmpid=3D701500000006y9H


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.   FRONT AND CENTER
       1.Time to Exclude Bad ISPs
       2.Standing on Other's Shoulders
II.  MICROSOFT VULNERABILITY SUMMARY
       1. Internet Explorer 8 CSS 'expression' Property Cross Site Script=
ing Filter Bypass Weakness
       2. Computer Associates ARCserve Backup 'LDBServer' Remote Code Exe=
cution Vulnerability
       3. Microsoft Internet Explorer XML Handling Remote Code Execution =
Vulnerability
       4. Microsoft WordPad Text Converter Remote Code Execution Vulnerab=
ility
       5. Microsoft SQL Server 2000 'sp_replwritetovarbin' Remote Memory =
Corruption Vulnerability
       6. Microsoft Outlook Express Malformed MIME Message Denial Of Serv=
ice Vulnerability
       7. RETIRED: RadASM '.rap' Project File Command Execution Vulnerabi=
lity
       8. IBM WebSphere Application Server Multiple Unspecified Vulnerabi=
lities
       9. DesignWorks Professional '.cct' File Buffer Overflow Vulnerabil=
ity
       10. Null FTP Server 'SITE' Command Arbitrary Command Injection Vul=
nerability
       11. Microsoft Windows Media Components ISATAP URL Handling Informa=
tion Disclosure Vulnerability
       12. Microsoft Windows Media Components 'Service Principle Name' Re=
mote Code Execution Vulnerability
       13. Microsoft Windows 'search-ms' Protocol Parsing Remote Code Exe=
cution Vulnerability
       14. Microsoft Windows Saved Search File Handling Remote Code Execu=
tion Vulnerability
       15. Microsoft Word RTF Malformed Control Word Variant 2 Remote Cod=
e Execution Vulnerability
       16. Microsoft SharePoint Server Unauthorized Access Vulnerability
       17. Microsoft Windows GDI File Size Parameter Heap Overflow Vulner=
ability
       18. Microsoft Windows GDI WMF Integer Overflow Vulnerability
       19. RETIRED: Microsoft December 2008 Advance Notification Multiple=
 Vulnerabilities
       20. Microsoft Excel Name Record Array Remote Code Execution Vulner=
ability
       21. Microsoft Excel Formula Handling Remote Code Execution Vulnera=
bility
       22. Microsoft Excel Malformed Object Handling Remote Code Executio=
n Vulnerability
       23. RadASM '.rap' Project File Buffer Overflow Vulnerability
       24. Microsoft Charts ActiveX Control Memory Corruption Vulnerabili=
ty
       25. Microsoft Windows Common AVI ActiveX Control File Parsing Buff=
er Overflow Vulnerability
       26. Microsoft Hierarchical FlexGrid ActiveX Control Memory Corrupt=
ion Vulnerability
       27. Microsoft Internet Explorer Navigation Method Remote Code Exec=
ution Vulnerability
       28. Microsoft Internet Explorer Embedded Object Remote Code Execut=
ion Vulnerability
       29. Microsoft Word RTF Malformed String Remote Code Execution Vuln=
erability
       30. Microsoft Internet Explorer Deleted Object Access Remote Code =
Execution Vulnerability
       31. Microsoft FlexGrid ActiveX Control Memory Corruption Vulnerabi=
lity
       32. Microsoft DataGrid ActiveX Control Memory Corruption Vulnerabi=
lity
       33. Microsoft Internet Explorer HTML Objects Remote Code Execution=
 Vulnerability
       34. Microsoft Word RTF Multiple Drawing Object Tags Remote Code Ex=
ecution Vulnerability
       35. Microsoft Word Malformed Record Value Remote Code Execution Vu=
lnerability
       36. Microsoft Word Malformed Value Remote Code Execution Vulnerabi=
lity
       37. Microsoft Word RTF '\do' Drawing Object Remote Heap Memory Cor=
ruption Vulnerability
       38. Microsoft Word ' FIB' Value Heap Memory Corruption Vulnerabili=
ty
       39. Microsoft Word RTF Polyline/Polygon Integer Overflow Vulnerabi=
lity
III. MICROSOFT FOCUS LIST SUMMARY
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Time to Exclude Bad ISPs
By Oliver Day
In recent months, three questionable Internet service providers - EstDoma=
ins, Atrivo, and McColo - were effectively taken offline resulting in not=
iceable drops of malware and spam.=20
http://www.securityfocus.com/columnists/487

2. Standing on Other's Shoulders
By Chris Wysopal
"If I have seen a little further it is by standing on the shoulders of Gi=
ants," Issac Netwon once wrote to describe how he felt that his scientifi=
c work was an extension of the work of those who went before him. In the =
scientific realm it is dishonorable not to credit those upon whose work y=
ou build.=20
http://www.securityfocus.com/columnists/486


II.  MICROSOFT VULNERABILITY SUMMARY
------------------------------------
1. Internet Explorer 8 CSS 'expression' Property Cross Site Scripting Fil=
ter Bypass Weakness
BugTraq ID: 32780
Remote: Yes
Date Published: 2008-12-11
Relevant URL: http://www.securityfocus.com/bid/32780
Summary:
Microsoft Internet Explorer is a web browser for the Microsoft Windows op=
erating system.

Internet Explorer 8 includes a cross-site-scripting filter that is design=
ed to prevent cross-site-scripting attacks against vulnerable web applica=
tions. Attackers may be able to bypass this filter under certain conditio=
ns, such as by taking advantage of an existing vulnerability in a web app=
lication.
=20
 Internet Explorer 8 beta 2 is vulnerable.

2. Computer Associates ARCserve Backup 'LDBServer' Remote Code Execution =
Vulnerability
BugTraq ID: 32764
Remote: Yes
Date Published: 2008-12-10
Relevant URL: http://www.securityfocus.com/bid/32764
Summary:
Computer Associates ARCserve Backup is prone to a remote code-execution v=
ulnerability.

Successfully exploiting this issue will allow attackers to execute arbitr=
ary code with SYSTEM-level privileges, completely compromising affected c=
omputers. Failed exploit attempts will likely crash the affected 'LDBserv=
er' service.

3. Microsoft Internet Explorer XML Handling Remote Code Execution Vulnera=
bility
BugTraq ID: 32721
Remote: Yes
Date Published: 2008-12-09
Relevant URL: http://www.securityfocus.com/bid/32721
Summary:
Microsoft Internet Explorer is prone to a remote code-execution vulnerabi=
lity.
=20
 Attackers can exploit this issue to execute arbitrary code in the contex=
t of the user running the application. Successful exploits will compromis=
e the application and possibly the underlying computer. Failed attacks wi=
ll cause denial-of-service conditions.

NOTE: Symantec has received reports that this issue is being actively exp=
loited in the wild.

4. Microsoft WordPad Text Converter Remote Code Execution Vulnerability
BugTraq ID: 32718
Remote: Yes
Date Published: 2008-12-09
Relevant URL: http://www.securityfocus.com/bid/32718
Summary:
Microsoft WordPad is prone to a remote code-execution vulnerability becau=
se of an unspecified error that may result in corrupted memory.

An attacker could exploit this issue to execute arbitrary code with the p=
rivileges of the currently logged-in user. Failed exploit attempts may re=
sult in denial-of-service conditions.

5. Microsoft SQL Server 2000 'sp_replwritetovarbin' Remote Memory Corrupt=
ion Vulnerability
BugTraq ID: 32710
Remote: Yes
Date Published: 2008-12-09
Relevant URL: http://www.securityfocus.com/bid/32710
Summary:
Microsoft SQL Server 2000 is prone to a remote memory-corruption vulnerab=
ility because it fails to properly handle user-supplied input.

Authenticated attackers can exploit this issue to execute arbitrary code =
and completely compromise affected computers. Failed attacks will likely =
cause denial-of-service conditions.

The issue affects Microsoft SQL Server 2000.

6. Microsoft Outlook Express Malformed MIME Message Denial Of Service Vul=
nerability
BugTraq ID: 32702
Remote: Yes
Date Published: 2008-12-08
Relevant URL: http://www.securityfocus.com/bid/32702
Summary:
Microsoft Outlook Express is prone to a denial-of-service vulnerability b=
ecause the application fails to properly handle malformed multipart MIME =
messages.

An attacker can exploit this issue to crash the application during delive=
ry.

7. RETIRED: RadASM '.rap' Project File Command Execution Vulnerability
BugTraq ID: 32687
Remote: Yes
Date Published: 2008-12-08
Relevant URL: http://www.securityfocus.com/bid/32687
Summary:
RadASM is prone to a command-execution vulnerability because it fails to =
perform adequate checks on user-supplied input.

Attackers may leverage this issue to execute arbitrary commands in the co=
ntext of the application. This may aid in further attacks.

 RadASM 2.2.1.5 is vulnerable; other versions may also be affected.

 NOTE: This BID is being retired because it has been determined not to be=
 a vulnerability.

8. IBM WebSphere Application Server Multiple Unspecified Vulnerabilities
BugTraq ID: 32679
Remote: Yes
Date Published: 2008-12-05
Relevant URL: http://www.securityfocus.com/bid/32679
Summary:
IBM WebSphere Application Server  (WAS) is prone to multiple vulnerabilit=
ies.

Attackers can exploit one of the issues to obtain sensitive information.

The impact of the other issues cannot be determined due to lack of techni=
cal information at this time. We will update this BID as more information=
 emerges.

These vulnerabilities affect WAS 7.0.

9. DesignWorks Professional '.cct' File Buffer Overflow Vulnerability
BugTraq ID: 32667
Remote: Yes
Date Published: 2008-12-06
Relevant URL: http://www.securityfocus.com/bid/32667
Summary:
DesignWorks Professional is prone to a buffer-overflow vulnerability beca=
use it fails to perform adequate checks on user-supplied input.

Attackers may leverage this issue to execute arbitrary code in the contex=
t of the application. Failed attacks will cause denial-of-service conditi=
ons.
=20
 DesignWorks Professional 4.3.1 is vulnerable; other versions may also be=
 affected.

10. Null FTP Server 'SITE' Command Arbitrary Command Injection Vulnerabil=
ity
BugTraq ID: 32656
Remote: Yes
Date Published: 2008-12-05
Relevant URL: http://www.securityfocus.com/bid/32656
Summary:
Null FTP Server is prone to an arbitrary-command-injection vulnerability =
because it fails to sufficiently sanitize user-supplied input.

An attacker can exploit this issue to execute arbitrary commands in the c=
ontext of the user running the application.

Null FTP Server 1.1.0.7 is vulnerable; prior versions may also be affecte=
d.

11. Microsoft Windows Media Components ISATAP URL Handling Information Di=
sclosure Vulnerability
BugTraq ID: 32654
Remote: Yes
Date Published: 2008-12-09
Relevant URL: http://www.securityfocus.com/bid/32654
Summary:
Microsoft Windows Media Components is prone to an information-disclosure =
vulnerability when handling 'ISATAP' (Intra-Site Automatic Tunnel Address=
ing Protocol) URLs.

An attacker can use this vulnerability to obtain information that may aid=
 in further attacks.

12. Microsoft Windows Media Components 'Service Principle Name' Remote Co=
de Execution Vulnerability
BugTraq ID: 32653
Remote: Yes
Date Published: 2008-12-09
Relevant URL: http://www.securityfocus.com/bid/32653
Summary:
Microsoft Windows Media Components is prone to a remote code-execution vu=
lnerability in the SPN (Service Principle Name) implementation.

A successful exploit of this vulnerability may allow a remote attacker to=
 execute code in the context of the logged-in user.

13. Microsoft Windows 'search-ms' Protocol Parsing Remote Code Execution =
Vulnerability
BugTraq ID: 32652
Remote: Yes
Date Published: 2008-12-09
Relevant URL: http://www.securityfocus.com/bid/32652
Summary:
Microsoft Windows Explorer is prone to a remote code-execution vulnerabil=
ity that affects the 'search-ms' protocol handler.

An attacker could exploit this issue by enticing a victim to visit a mali=
ciously crafted website.

Successfully exploiting this issue would allow the attacker to execute ar=
bitrary code in the context of the currently logged-in user.

This issue affects Windows Vista and Windows Server 2008.

NOTE: Supported editions of Windows Server 2008 are not affected if insta=
lled using the Server Core installation option.

14. Microsoft Windows Saved Search File Handling Remote Code Execution Vu=
lnerability
BugTraq ID: 32651
Remote: Yes
Date Published: 2008-12-09
Relevant URL: http://www.securityfocus.com/bid/32651
Summary:
Microsoft Windows is prone to a remote code-execution vulnerability becau=
se Windows Explorer fails to correctly free memory when saving the Window=
s Search saved-search files.

Attackers may exploit this issue by enticing victims into opening and sav=
ing a maliciously crafted saved-search file.=20

Successful exploits may allow attackers to execute arbitrary code with th=
e privileges of the user running the application. Failed exploit attempts=
 will likely result in denial-of-service conditions.

This issue affects Windows Vista and Windows Server 2008.

NOTE: Supported editions of Windows Server 2008 are not affected if insta=
lled using the Server Core installation option.

15. Microsoft Word RTF Malformed Control Word Variant 2 Remote Code Execu=
tion Vulnerability
BugTraq ID: 32642
Remote: Yes
Date Published: 2008-12-09
Relevant URL: http://www.securityfocus.com/bid/32642
Summary:
Microsoft Word is prone to a remote code-execution vulnerability.

An attacker could exploit this issue by enticing a victim to open a malic=
ious RTF file.=20

Successfully exploiting this issue would allow the attacker to execute ar=
bitrary code in the context of the currently logged-in user.

16. Microsoft SharePoint Server Unauthorized Access Vulnerability
BugTraq ID: 32638
Remote: Yes
Date Published: 2008-12-09
Relevant URL: http://www.securityfocus.com/bid/32638
Summary:
Microsoft SharePoint Server is prone to a vulnerability that could let re=
mote attackers gain unauthorized access. A successful exploit will let at=
tackers access certain administrative functions of the SharePoint  Server=
.

17. Microsoft Windows GDI File Size Parameter Heap Overflow Vulnerability
BugTraq ID: 32637
Remote: Yes
Date Published: 2008-12-09
Relevant URL: http://www.securityfocus.com/bid/32637
Summary:
The GDI component of Microsoft Windows is prone to a heap-overflow vulner=
ability that may be triggered by a malicious WMF (Windows Metafile) image=
. A successful exploit will let the attacker execute arbitrary code in th=
e context of the currently logged-in user.

18. Microsoft Windows GDI WMF Integer Overflow Vulnerability
BugTraq ID: 32634
Remote: Yes
Date Published: 2008-12-09
Relevant URL: http://www.securityfocus.com/bid/32634
Summary:
The GDI component of Microsoft Windows is prone to an integer-overflow vu=
lnerability that may be triggered by a malicious WMF (Windows Metafile) i=
mage. A successful exploit will let the attacker execute arbitrary code i=
n the context of the currently logged-in user.

19. RETIRED: Microsoft December 2008 Advance Notification Multiple Vulner=
abilities
BugTraq ID: 32632
Remote: Yes
Date Published: 2008-12-04
Relevant URL: http://www.securityfocus.com/bid/32632
Summary:
Microsoft has released advance notification that the vendor will be relea=
sing eight security bulletins on December 9, 2008. The highest severity r=
ating for these issues is 'Critical'.

Successfully exploiting these issues may allow remote or local attackers =
to compromise affected computers.

The following individual records cover these issues:

30674 Microsoft Visual Studio 'Msmask32.ocx' ActiveX Control Remote Buffe=
r Overflow Vulnerability
32591 Microsoft DataGrid ActiveX Control Memory Corruption Vulnerability
32592 Microsoft FlexGrid ActiveX Control Memory Corruption Vulnerability
32612 Microsoft Hierarchical FlexGrid ActiveX Control Memory Corruption V=
ulnerability
32613 Microsoft Windows Common AVI ActiveX Control File Parsing Memory Co=
rruption Vulnerability
32614 Microsoft Charts ActiveX Control Memory Corruption Vulnerability
32634 Microsoft Windows GDI WMF Integer Overflow Vulnerability=20
32637 Microsoft Windows GDI File Size Parameter Heap Overflow Vulnerabili=
ty
32580 Microsoft Word Malformed Record Remote Code Execution Vulnerability
32579 Microsoft Word RTF Malformed Control Word Remote Code Execution Vul=
nerability
32583 Microsoft Word Malformed Value Remote Code Execution Vulnerability
32581 Microsoft Word RTF Malformed Control Word Variant 1 Remote Code Exe=
cution Vulnerability
32585 Microsoft Word RTF Malformed Control Word Variant 3 Remote Code Exe=
cution Vulnerability
32642 Microsoft Word RTF Malformed Control Word Variant 2 Remote Code Exe=
cution Vulnerability
32594 Microsoft Word RTF Malformed String Remote Code Execution Vulnerabi=
lity
32584 Microsoft Word Malformed Record Value Remote Code Execution Vulnera=
bility
32596 Microsoft Internet Explorer Navigation Method Remote Code Execution=
 Vulnerability
32586 Microsoft Internet Explorer HTML Objects Remote Code Execution Vuln=
erability=20
32593 Microsoft Internet Explorer Deleted Object Access Remote Code Execu=
tion Vulnerability
32595 Microsoft Internet Explorer Embedded Object Remote Code Execution V=
ulnerability
32621 Microsoft Excel Formula Handling Remote Code Execution Vulnerabilit=
y
32618 Microsoft Excel Malformed Object Handling Remote Code Execution Vul=
nerability
32622 Microsoft Excel Global Array Memory Corruption Vulnerability
32651 Microsoft Windows Search Saved Search File Handling Remote Code Exe=
cution Vulnerability
32652 Microsoft Windows Search 'search-ms' Protocol Parsing Remote Code E=
xecution Vulnerability
32653 Microsoft Media Components 'Service Principle Name' Remote Code Exe=
cution Vulnerability
32654 Microsoft Media Components 'ISATAP' Information Disclosure Vulnerab=
ility
32638 Microsoft SharePoint Server Unauthorized Access Vulnerability

20. Microsoft Excel Name Record Array Remote Code Execution Vulnerability
BugTraq ID: 32622
Remote: Yes
Date Published: 2008-12-09
Relevant URL: http://www.securityfocus.com/bid/32622
Summary:
Microsoft Excel is prone to a remote code-execution vulnerability.

Attackers may exploit this issue by enticing victims into opening a malic=
iously crafted Excel file.

Successful exploits may allow attackers to execute arbitrary code with th=
e privileges of the user running the application.

21. Microsoft Excel Formula Handling Remote Code Execution Vulnerability
BugTraq ID: 32621
Remote: Yes
Date Published: 2008-12-09
Relevant URL: http://www.securityfocus.com/bid/32621
Summary:
Microsoft Excel is prone to a remote code-execution vulnerability.

Attackers may exploit this issue by enticing victims into opening a malic=
iously crafted Excel file.

Successful exploits may allow attackers to execute arbitrary code with th=
e privileges of the user running the application.

22. Microsoft Excel Malformed Object Handling Remote Code Execution Vulne=
rability
BugTraq ID: 32618
Remote: Yes
Date Published: 2008-12-09
Relevant URL: http://www.securityfocus.com/bid/32618
Summary:
Microsoft Excel is prone to a remote code-execution vulnerability.

Attackers may exploit this issue by enticing victims into opening a malic=
iously crafted Excel file.

Successful exploits may allow attackers to execute arbitrary code with th=
e privileges of the user running the application.

23. RadASM '.rap' Project File Buffer Overflow Vulnerability
BugTraq ID: 32617
Remote: Yes
Date Published: 2008-12-03
Relevant URL: http://www.securityfocus.com/bid/32617
Summary:
RadASM is prone to a buffer-overflow vulnerability because it fails to pe=
rform adequate checks on user-supplied input.

Attackers may leverage this issue to execute arbitrary code in the contex=
t of the application. Failed attacks will cause denial-of-service conditi=
ons.
=20
 RadASM 2.2.1.4 is vulnerable; other versions may also be affected.

24. Microsoft Charts ActiveX Control Memory Corruption Vulnerability
BugTraq ID: 32614
Remote: Yes
Date Published: 2008-12-09
Relevant URL: http://www.securityfocus.com/bid/32614
Summary:
Microsoft Charts ActiveX control is prone to a remote memory-corruption v=
ulnerability.

Remote attackers can exploit this issue to execute arbitrary code in the =
context of the application using the ActiveX control (typically Internet =
Explorer). Successful exploits will compromise the application and possib=
ly the underlying computer. Failed attacks will cause denial-of-service c=
onditions.

25. Microsoft Windows Common AVI ActiveX Control File Parsing Buffer Over=
flow Vulnerability
BugTraq ID: 32613
Remote: Yes
Date Published: 2008-12-09
Relevant URL: http://www.securityfocus.com/bid/32613
Summary:
Microsoft Windows Common AVI ActiveX control is prone to a remote buffer-=
overflow vulnerability.

Remote attackers can exploit this issue to execute arbitrary code in the =
context of the application using the ActiveX control (typically Internet =
Explorer). Successful exploits will compromise the application and possib=
ly the underlying computer. Failed attacks will cause denial-of-service c=
onditions.

26. Microsoft Hierarchical FlexGrid ActiveX Control Memory Corruption Vul=
nerability
BugTraq ID: 32612
Remote: Yes
Date Published: 2008-12-09
Relevant URL: http://www.securityfocus.com/bid/32612
Summary:
Microsoft Hierarchical FlexGrid ActiveX control is prone to a remote memo=
ry-corruption vulnerability.

Remote attackers can exploit this issue to execute arbitrary code in the =
context of the application using the ActiveX control (typically Internet =
Explorer). Successful exploits will compromise the application and possib=
ly the underlying computer. Failed attacks will cause denial-of-service c=
onditions.

Microsoft Hierarchical FlexGrid Control 6.0.88.4 is vulnerable; other ver=
sions may also be affected.  The control is bundled with Microsoft Visual=
 Basic 6.0 and Microsoft Visual FoxPro 8.0 SP1 and 9.0 SP 2.

27. Microsoft Internet Explorer Navigation Method Remote Code Execution V=
ulnerability
BugTraq ID: 32596
Remote: Yes
Date Published: 2008-12-09
Relevant URL: http://www.securityfocus.com/bid/32596
Summary:
Microsoft Internet Explorer is prone to a remote code-execution vulnerabi=
lity.

Attackers can exploit this issue to execute arbitrary code in the context=
 of the user running the application. Successful exploits will compromise=
 the application and possibly the underlying computer. Failed attacks wil=
l cause denial-of-service conditions.

28. Microsoft Internet Explorer Embedded Object Remote Code Execution Vul=
nerability
BugTraq ID: 32595
Remote: Yes
Date Published: 2008-12-09
Relevant URL: http://www.securityfocus.com/bid/32595
Summary:
Microsoft Internet Explorer is prone to a remote code-execution vulnerabi=
lity.

Attackers can exploit this issue to execute arbitrary code in the context=
 of the user running the application. Successful exploits will compromise=
 the application and possibly the underlying computer. Failed attacks wil=
l cause denial-of-service conditions.

29. Microsoft Word RTF Malformed String Remote Code Execution Vulnerabili=
ty
BugTraq ID: 32594
Remote: Yes
Date Published: 2008-12-09
Relevant URL: http://www.securityfocus.com/bid/32594
Summary:
Microsoft Word is prone to a remote code-execution vulnerability.

An attacker could exploit this issue by enticing a victim to open a malic=
ious RTF file.=20

Successfully exploiting this issue would allow the attacker to execute ar=
bitrary code in the context of the currently logged-in user.

30. Microsoft Internet Explorer Deleted Object Access Remote Code Executi=
on Vulnerability
BugTraq ID: 32593
Remote: Yes
Date Published: 2008-12-09
Relevant URL: http://www.securityfocus.com/bid/32593
Summary:
Microsoft Internet Explorer is prone to a remote code-execution vulnerabi=
lity.

Attackers can exploit this issue to execute arbitrary code in the context=
 of the user running the application. Successful exploits will compromise=
 the application and possibly the underlying computer. Failed attacks wil=
l cause denial-of-service conditions.

31. Microsoft FlexGrid ActiveX Control Memory Corruption Vulnerability
BugTraq ID: 32592
Remote: Yes
Date Published: 2008-12-09
Relevant URL: http://www.securityfocus.com/bid/32592
Summary:
Microsoft FlexGrid ActiveX control is prone to a remote memory-corruption=
 vulnerability.

Remote attackers can exploit this issue to execute arbitrary code in the =
context of the application using the ActiveX control (typically Internet =
Explorer). Successful exploits will compromise the application and possib=
ly the underlying computer. Failed attacks will cause denial-of-service c=
onditions.

32. Microsoft DataGrid ActiveX Control Memory Corruption Vulnerability
BugTraq ID: 32591
Remote: Yes
Date Published: 2008-12-09
Relevant URL: http://www.securityfocus.com/bid/32591
Summary:
Microsoft DataGrid ActiveX control is prone to a remote memory-corruption=
 vulnerability.

Remote attackers can exploit this issue to execute arbitrary code in the =
context of the application using the ActiveX control (typically Internet =
Explorer). Successful exploits will compromise the application and possib=
ly the underlying computer. Failed attacks will cause denial-of-service c=
onditions.

33. Microsoft Internet Explorer HTML Objects Remote Code Execution Vulner=
ability
BugTraq ID: 32586
Remote: Yes
Date Published: 2008-12-09
Relevant URL: http://www.securityfocus.com/bid/32586
Summary:
Microsoft Internet Explorer is prone to a remote code-execution vulnerabi=
lity.

Attackers can exploit this issue to execute arbitrary code in the context=
 of the user running the application. Successful exploits will compromise=
 the application and possibly the underlying computer. Failed attacks wil=
l cause denial-of-service conditions.

34. Microsoft Word RTF Multiple Drawing Object Tags Remote Code Execution=
 Vulnerability
BugTraq ID: 32585
Remote: Yes
Date Published: 2008-12-09
Relevant URL: http://www.securityfocus.com/bid/32585
Summary:
Microsoft Word is prone to a remote code-execution vulnerability.

An attacker could exploit this issue by enticing a victim to open a malic=
ious RTF file.=20

Successfully exploiting this issue would allow the attacker to execute ar=
bitrary code in the context of the currently logged-in user.

35. Microsoft Word Malformed Record Value Remote Code Execution Vulnerabi=
lity
BugTraq ID: 32584
Remote: Yes
Date Published: 2008-12-09
Relevant URL: http://www.securityfocus.com/bid/32584
Summary:
Microsoft Word is prone to a remote code-execution vulnerability.

An attacker can exploit this issue to execute arbitrary code in the conte=
xt of the currently logged-in user. Failed exploit attempts will likely r=
esult in denial-of-service conditions.

36. Microsoft Word Malformed Value Remote Code Execution Vulnerability
BugTraq ID: 32583
Remote: Yes
Date Published: 2008-12-09
Relevant URL: http://www.securityfocus.com/bid/32583
Summary:
Microsoft Word is prone to a remote code-execution vulnerability.

An attacker can exploit this issue to execute arbitrary code in the conte=
xt of the currently logged-in user. Failed exploit attempts will likely r=
esult in denial-of-service conditions.

37. Microsoft Word RTF '\do' Drawing Object Remote Heap Memory Corruption=
 Vulnerability
BugTraq ID: 32581
Remote: Yes
Date Published: 2008-12-09
Relevant URL: http://www.securityfocus.com/bid/32581
Summary:
Microsoft Word is prone to a remote heap memory-corruption vulnerability.

An attacker could exploit this issue by enticing a victim to open a malic=
ious RTF file.=20

Successfully exploiting this issue would allow the attacker to execute ar=
bitrary code in the context of the currently logged-in user.

38. Microsoft Word ' FIB' Value Heap Memory Corruption Vulnerability
BugTraq ID: 32580
Remote: Yes
Date Published: 2008-12-09
Relevant URL: http://www.securityfocus.com/bid/32580
Summary:
Microsoft Word is prone to a heap-based memory-corruption vulnerability.=20

An attacker can exploit this issue by sending a specially crafted Word fi=
le to an unsuspecting user and enticing them to open it with a vulnerable=
 application. A successful exploit will allow attackers to execute arbitr=
ary code within the context of the user running the affected application.

39. Microsoft Word RTF Polyline/Polygon Integer Overflow Vulnerability
BugTraq ID: 32579
Remote: Yes
Date Published: 2008-12-09
Relevant URL: http://www.securityfocus.com/bid/32579
Summary:
Microsoft Word is prone to an integer-overflow vulnerability because the =
application fails to perform adequate boundary checks on user-supplied da=
ta.

An attacker could exploit this issue by enticing a victim to open a malic=
ious RTF file.=20

Successfully exploiting this issue would allow the attacker to execute ar=
bitrary code in the context of the currently logged-in user.

III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to ms-secnews-unsubscribe@securityf=
ocus.com from the subscribed address. The contents of the subject or mess=
age body do not matter. You will receive a confirmation request message t=
o which you will have to answer. Alternatively you can also visit http://=
www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This issue is sponsored by Ironkey: The World's Most Secure Flash Drive

IronKey flash dives lock down your most sensitive data using today's most=
 advanced security technology.=20
IronKey uses military-grade AES CBC-mode hardware encryption that cannot =
be disabled by malware or an intruder and provides rugged and waterproof =
protection to safeguard your data.
https://www.ironkey.com/secure-flash-drive1a?cmpid=3D701500000006y9H