Double Clicking on Office Documents Could Execute Arbitrary Code.Double Clicking on Office Documents Could Execute Arbitrary Code.
A vulnerbility discovered with the use of specific DLL files could cause arbitrary code to be executed on a Windows 98 or Windows 2000 machine.
September 17, 2000
Reported September 18, 2000 by Georgi Guninski VERSIONS AFFECTED DESCRIPTIONIf certain DLL files are present on a system running Windows 98 or Windows 2000 they can be exploited to execute native code. This could lead to an attacker gaining full control over a system. It has been reported that this attack also works via UNC shares. DEMONSTRATION If either RICHED20.DLL or MSI.DLL are present on the system and in the same directory as Office documents double clicking on the Office documents will execute the code in DllMain () of the above DLLs. A demonstration of this vulnerability is available at; http://www.guninski.com VENDOR RESPONSE Georgie Guninski made no indication that the vendor has been contacted. Windows IT Security forwarded the advisory to Microsoft and is awaiting a response. CREDITDiscovered by Georgi Guninski |
About the Author
You May Also Like