Privacy and Legal Notice

CIAC INFORMATION BULLETIN

Q-274: Vulnerability in Microsoft Visual Basic for Application

[Microsoft Security Bulletin MS06-047 (921645)]

August 8, 2006 21:00 GMT

PROBLEM: A remote code execution vulnerability exists in the way that Visual Basic for Applications (VBA) checks the document properties that a host application passes to it when opening a document.
PLATFORM: Tested Software and Security Update Download Locations:
Affected Software:
• Microsoft Office 2000 Service Pack 3
• Microsoft Project 2000 Service Release 1
• Microsoft Access 2000 Runtime Service Pack 3
• Microsoft Office XP Service Pack 3
• Microsoft Project 2002 Service Pack 1
• Microsoft Visio 2002 Service Pack 2
• Microsoft Works Suites:
• Microsoft Works Suite 2004 (same as the Microsoft Office XP update)
• Microsoft Works Suite 2005 (same as the Microsoft Office XP update)
• Microsoft Works Suite 2006 (same as the Microsoft Office XP update)
• Microsoft Visual Basic for Applications SDK 6.0
• Microsoft Visual Basic for Applications SDK 6.2
• Microsoft Visual Basic for Applications SDK 6.3
• Microsoft Visual Basic for Applications SDK 6.4

Non-Affected Software:
• Microsoft Office 2003 Service Pack 1 and Microsoft Office 2003 Service Pack 2
DAMAGE: Remote code execution.
SOLUTION: Upgrade to the appropriate version.

VULNERABILITY
ASSESSMENT:
The risk is HIGH. A remote code execution.

LINKS:  
  CIAC BULLETIN: http://www.ciac.org/ciac/bulletins/q-274.shtml
  ORIGINAL BULLETIN: http://www.microsoft.com/technet/security/bulletin/ms06-047.mspx
   Microsoft Security Bulletin MS06-047 (921645)
  CVE: CVE-2006-3649

[***** Start Microsoft Security Bulletin MS06-047 (921645) *****]


Microsoft Security Bulletin MS06-047

Vulnerability in Microsoft Visual Basic for Applications Could Allow Remote Code Execution (921645)

Published: August 8, 2006

Version: 1.0

Summary

Who Should Read this Document: Customers using Microsoft Office applications or applications that use Microsoft Visual Basic for Applications.

Impact of Vulnerability: Remote Code Execution

Maximum Severity Rating: Critical

Recommendation: Customers should apply the update immediately

Security Update Replacement: This bulletin replaces a prior security update. See the frequently asked questions (FAQ) section of this bulletin for the complete list.

Caveats: None

Tested Software and Security Update Download Locations:

Affected Software:

Microsoft Office 2000 Service Pack 3 — Download the update (KB920822)

Microsoft Project 2000 Service Release 1 — Download the update (KB920822)

Microsoft Access 2000 Runtime Service Pack 3 — Download the update (KB920822)

Microsoft Office XP Service Pack 3 — Download the update (KB920821)

Microsoft Project 2002 Service Pack 1 — Download the update (KB920821)

Microsoft Visio 2002 Service Pack 2 — Download the update (KB920821)

Microsoft Works Suites:

Microsoft Works Suite 2004 — Download the update (KB920821) (same as the Microsoft Office XP update)

Microsoft Works Suite 2005 — Download the update (KB920821) (same as the Microsoft Office XP update)

Microsoft Works Suite 2006 — Download the update (KB920821) (same as the Microsoft Office XP update)

Microsoft Visual Basic for Applications SDK 6.0 — Download the update (KB923167)

Microsoft Visual Basic for Applications SDK 6.2 — Download the update (KB923167)

Microsoft Visual Basic for Applications SDK 6.3 — Download the update (KB923167)

Microsoft Visual Basic for Applications SDK 6.4 — Download the update (KB923167)

Non-Affected Software:

Microsoft Office 2003 Service Pack 1 and Microsoft Office 2003 Service Pack 2

The software in this list has been tested to determine whether the versions are affected. Other versions either no longer include security update support or may not be affected. To determine the support life cycle for your product and version, visit the Microsoft Support Lifecycle Web site.

Top of sectionTop of section

General Information

Executive Summary

Executive Summary:

This update resolves a newly discovered, privately reported vulnerability. The vulnerability is documented in the "Vulnerability Details" section of this bulletin.

On vulnerable versions of Office or Microsoft Visual Basic for Applications, if a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

We recommend that customers apply the update immediately.

Severity Ratings and Vulnerability Identifiers:

Vulnerability Identifiers Impact of Vulnerability Microsoft Office 2000 Microsoft Office XP Microsoft Visual Basic for Applications SDK 6.0, 6.2, 6.3 and 6.4

Visual Basic for Applications Vulnerability - CVE-2006-3649

Remote Code Execution

Critical

Important

Important

Note The severity ratings for Microsoft Works Suite maps to the Microsoft Office versions as follows:

The Microsoft Works Suite 2004, 2005, and 2006 severity rating is the same as the Microsoft Office XP severity rating.

This assessment is based on the types of systems that are affected by the vulnerability, their typical deployment patterns, and the effect that exploiting the vulnerability would have on them.

Frequently Asked Questions (FAQ) Related to This Security Update

Vulnerability Details

Visual Basic for Applications Vulnerability - CVE-2006-3649

Security Update Information

Affected Software:

For information about the specific security update for your affected software, click the appropriate link:

Office XP

Office 2000