RULE(RULE ID:710936)

Rule General Information
Release Date: 2014-11-11
Rule Name: Microsoft Word RTF File Handling Memory Corruption Vulnerability (CVE-2008-1091)
Severity:
CVE ID:
CNNVD ID:
Rule Protection Details
Description: Unspecified vulnerability in Microsoft Word in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 Office System SP1 and earlier allows remote attackers to execute arbitrary code via a Rich Text Format (.rtf) file with a malformed string that triggers a "memory calculation error" and a heap-based buffer overflow.
Impact: An attacker can execute arbitrary code in the context of the vulnerable system. Failed exploit may cause denial-of-service attack.
Affected OS: Windows
Reference: MicrosoftSecurityBulletin:ms08-026
SecurityFocusBID:29104
SecurityTrackerID:1020013
Solutions
Microsoft has released a patch MS08-026 to eliminate the vulnerability. The patch can be downloaded at http://www.microsoft.com/technet/security/bulletin/ms08-026.mspx