• Earn real money by being active: Hello Guest, earn real money by simply being active on the forum — post quality content, get reactions, and help the community. Once you reach the minimum credit amount, you’ll be able to withdraw your balance directly. Learn how it works.

Exploits Microsoft Word Local Machine Zone Remote Code Execution Vulnerability

Status
Not open for further replies.

sniffer

LvL-23
User
Joined
Apr 15, 2012
Messages
37
Reputation
0
Reaction score
272
Points
53
Credits
0
‎13 Years of Service‎
74%
Exploit Title: Microsoft Word Local Machine Zone Remote Code Execution Vulnerability

Date: July 15th, 2015

Exploit Author: Eduardo Braun Prado

Vendor Homepage :
This link is hidden for visitors. Please Log in or register now.


Version: 2007

Tested on: Microsoft Windows XP, 2003, Vista, 2008, 7, 8, 8.1

CVE: CVE-2015-0097

Original Advisory:
This link is hidden for visitors. Please Log in or register now.


Microsoft Word, Excel and Powerpoint 2007 contains a remote code execution vulnerability because it is possible to reference documents such as Works document (.wps) as HTML. It will process HTML and script code in the context of the local machine zone of Internet Explorer which leads to arbitrary code execution. By persuading users into opening eg. specially crafted .WPS, ".doc ", ".RTF " (with a space at the end) it is possible to triggerthe vulnerability and run arbitrary code in the context of the logged on Windows user.

Exploit code here :

This link is hidden for visitors. Please Log in or register now.


This link is hidden for visitors. Please Log in or register now.


This link is hidden for visitors. Please Log in or register now.


 
Status
Not open for further replies.
Back
Top