Preemptive Protection against Microsoft Office BMP Integer Overflow Vulnerability (MS09-062)
| Check Point Reference: | CPAI-2009-208 | |
| Date Published: | ||
| Preemptive Since: | ||
| Severity: | ||
| Source: | Microsoft Security Bulletin MS09-062 | |
| Industry Reference(s): | CVE-2009-2518 | |
| Protection Provided by: |
Security Gateway
|
|
| Who is Vulnerable? Microsoft Office XP SP3 | ||
| Vulnerability Description A remote code execution vulnerability has been discovered in the way that Microsoft Office handles specially crafted Office Documents containing BMP images. BMP is an image file format used to store bitmap digital images. A remote attacker could exploit this issue via a malformed BMP file. Successful exploitation of this vulnerability may allow execution of arbitrary code on a target system. |
||
|
Update/Patch Available Apply patches: Microsoft Security Bulletin MS09-062 |
|
|
Vulnerability Details The vulnerability is due to an error in GDI+ that fails to properly parse BMP files with malformed headers. A remote attacker could trigger this flaw by convincing a victim to open an office file that contains a specially crafted BMP file. Successful exploitation of this issue may allow the attacker to take complete control of the affected system. |
Protection Overview
This protection will detect and block the transferring of malformed BMP files over HTTP.
Users are protected against this vulnerability if the protection for blocking malformed BMP files in the Protection section of CPAI-2008-116 has been applied.
To configure the defense, select your product from the list below and follow the related protection steps.