Workaround for Multiple Microsoft Visio Vulnerabilities (MS08-019)
| Check Point Reference: | SBP-2008-05 | |
| Date Published: | ||
| Severity: | ||
| Source: | Microsoft Security Bulletin MS08-019 | |
| Industry Reference(s): | CVE-2008-1089 CVE-2008-1090 |
|
| Protection Provided by: |
VPN-1
|
|
| Who is Vulnerable? Microsoft Office XP SP3 Microsoft Office 2003 SP2 Microsoft Office 2003 SP3 2007 Microsoft Office System 2007 Microsoft Office System SP1 | ||
| Vulnerability Description Multiple remote code execution vulnerabilities have been reported in Microsoft Visio. Microsoft Visio is a diagram creation software for Microsoft Windows. A remote attacker can exploit these vulnerabilities via a specially crafted Visio file. Successful exploitation may allow execution of arbitrary code on a vulnerable system. |
||
|
Update/Patch Available Apply patches: Microsoft Security Bulletin MS08-019 |
|
|
Vulnerability Details CVE-2008-1089: The vulnerability is due to an error in Microsoft Visio that fails to properly validate object header data when opening Visio files. CVE-2008-1090: The vulnerability is due to an error in Microsoft Visio that fails to properly validate memory allocations when loading specially crafted Visio files from disk into memory. A remote attacker could trigger these flaws by convincing the victim to open a specially crafted Visio file (.VSD, VSS, or .VST). Successful exploitation of these issues allows execution of arbitrary code once a malformed Visio file is being loaded on a vulnerable system. |
Protection Overview
By enabling this protection, SmartDefense will detect and block the transferring of Microsoft Visio files over HTTP. No update is required to address this vulnerability.
Since the protection offered in this advisory may degrade performance and block access to legitimate files, users are advised to use this protection as a workaround till all systems are patched.
Users are protected against this vulnerability if the Protection against Microsoft Visio Remote Code Execution addressed in CPAI-2007-074 has been applied.
To configure the defense, select your product from the list below and follow the related protection steps.