Microsoft Word 2007 - Multiple Vulnerabilities

Author: muts
type: dos
platform: windows
port: 
date_added: 2007-04-08  
date_updated: 2017-08-14  
verified: 1  
codes: OSVDB-37634;CVE-2007-1911;OSVDB-37633;CVE-2007-1910  
tags:   
aliases: 04092007-0day.tar.gz  
screenshot_url:   
application_url:   

raw file: 3690.txt  
# Mati Aharoni

# muts [.@.] offensive-security.com

# http://www.offensive-security.com





My 7 line python fuzzer found several file format bugs in 3 hours. Quite alarming.

No deep analysis was done, I leave that to the community.

These are some of the results:



file789-1.doc  - Unspecified Overflow in word 2007 - Crash in wwlib.dll . Code execution is not trivial.

file798-1.doc . Word 2007 CPU exhaustion DOS - CPU shoots up to 100 %.

file613-1.doc -  Word 2007 CPU exhaustion DOS + ding - CPU shoots up to 100 %, and windows goes .ding!.



These files can be found at http://www.offensive-security.com/0day/0day.tar.gz

backup: https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/3690.tar.gz (04092007-0day.tar.gz)


Be safe,



Muts


# milw0rm.com [2007-04-09]