Home   |   Asp.Net 2.0   |   .Net Framework 2.0   |   IIS 6.0   |   Sql Server 2005   |   Visual Basic 2005   |   c# 2005   |   VS 2005   |   Visual Source Safe 2005

MS Dynamics CRM 3.0

SharePoint Portal Server 2003
SharePoint Server 2007
Dynamics NAV
Dynamics CRM
SharePoint Designer 2007
SharePoint Portal Server 2001
Windows SharePoint Services
Windows SharePoint Services 3.0
Project Server 2003
Project Server 2007
Dynamics – Point of Sale
Dynamics AX
Dynamics GP
Dynamics Retail Management System (RMS)
Dynamics SL
SQL Server 2000
Visual Basic .NET 2003
Visual C# .NET 2003
Visual C++ .NET 2003
Visual C++ 2005
Visual SourceSafe 6.0
Windows Server 2003
Windows Server 2003
Outlook 2003
ADO.NET 1.1
ASP.NET 1.0
Visual Studio Team Foundation Server
Visual Studio 2005 Team Edition
Windows Internet Explorer 7
BizTalk Server 2000
BizTalk Server 2002
BizTalk Server 2004
BizTalk Server 2006
Visual Studio 6.0
Access 2000
Access 2002
Access 2003
Access 2007
Access 97
Collaboration Data Objects 2.0
Commerce Server 2002
Content Management Server 2001
Commerce Server 2007
Content Management Server 2002
Data Access Components 2.7
Data Access Components 2.8
DirectX 9.0b
Office Small Business Accounting 2006
Accounting 2007
ActiveSync 4.1
Class Server 2.0
Groove 2007
Windows Vista
Outlook 2007
OneNote 2003
OneNote 2007
Office X for Mac
Zune software
Zune Live
Zoo Tycoon 2
Flight Simulator 2002
Dungeon Siege II

Cervo Technologies
The Right Source to Outsource

Oracle Database FAQS

Sharepoint Portal Server KB

Outlook 2007 Knowledge Base Articles

Dynamics GP Knowledge Base Articles

Microsoft Visual Basic for Applications (VBA) is based on the Microsoft Visual Basic development system. Microsoft Office products include VBA and use it to perform certain functions. You can use VBA to build customized programs that are based on an...


Microsoft Visual Basic for Applications (VBA) is based on the Microsoft Visual Basic development system. Microsoft Office products include VBA and use it to perform certain functions. You can use VBA to build customized programs that are based on an existing host program.

A flaw exists in the way VBA checks document properties passed to it when a document is opened by the host program. A buffer overrun exists which, if exploited successfully, could allow an attacker to execute code of their choice in the context of the logged on user.

For an attack to be successful, the logged on user would have to open a specially crafted document that was sent to them by an attacker. This document could be any type of document that supports VBA, such as a Microsoft Word document, a Microsoft Excel spreadsheet, or a Microsoft PowerPoint presentation. If Word is being used as the HTML e-mail editor for Microsoft Outlook, this document could be an e-mail message. However, the logged on user must reply to or forward the malicious e-mail message for the vulnerability to be exploited.

Mitigating factors
Logged-on users must open a document that is sent to them by an attacker for this vulnerability to be exploited.
If Word is being used as the HTML e-mail editor in Outlook, users must reply to or forward a malicious e-mail message that was sent to them by the attacker for this vulnerability to be exploited.
An attacker's code could only run with the same rights as the logged-on user. The specific privileges that the attacker could gain through this vulnerability would therefore depend on the privileges that are granted to the user who is logged on. Any limitations on the account of the user who is logged on , such as those applied through Group Policies, would also limit the actions of any arbitrary code that is executed by this vulnerability.

RESOLUTION

Security patch information

Download and installation information

If you are using any of the following programs, you should apply the VBA version of this patch:
Microsoft VBA 5.0
Microsoft VBA 6.0
Microsoft VBA 6.2
Microsoft VBA 6.3
Microsoft Access 97
Microsoft Excel 97
Microsoft PowerPoint 97
Microsoft Word 97
Microsoft Word 98(J)
Microsoft Works 2001
Microsoft Works 2002
Microsoft Works Suite 2003
Microsoft Business Solutions Great Plains 7.5
Microsoft Business Solutions Great Plains 7.0
Microsoft Business Solutions Great Plains 6.0
Microsoft Business Solutions Solomon IV 4.5
Microsoft Business Solutions Solomon IV 5.0
Microsoft Business Solutions Solomon IV 5.5
For more information about the Microsoft VBA patch, click the following article number to view the article in the Microsoft Knowledge Base: If you are using any of the following programs, you should apply the specific version of the patch for those products.
Microsoft Project 2000
Microsoft Project 2002
Microsoft Visio 2002
For more information about these security patches, click the following article numbers to view the articles in the Microsoft Knowledge Base:
If you are using any of the following programs, you should apply the specific version of the patch for those products.
Microsoft Office 2000
Microsoft Office XP (including Microsoft Publisher 2002)
For more information about these security patches, click the following article numbers to view the articles in the Microsoft Knowledge Base:

Removal information

You cannot remove this patch.

Patch replacement information

This patch does not replace any other hotfixes.

REFERENCES

For more information about these vulnerabilities, visit the following Microsoft Web site:
http://www.microsoft.com/technet/security/bulletin/MS03-037.mspx (http://www.microsoft.com/technet/security/bulletin/MS03-037.mspx)


APPLIES TO
Microsoft Visual Basic for Applications (VBA) Software Development Kit (SDK) 5.0
Microsoft Visual Basic for Applications (VBA) Software Development Kit (SDK) 6.0
Microsoft Visual Basic for Applications (VBA) Software Development Kit (SDK) 6.1
Microsoft Access 97 Standard Edition
Microsoft Access 2000 Standard Edition
Microsoft Access 2002 Standard Edition
Microsoft Excel 2000 Standard Edition
Microsoft Excel 2002 Standard Edition
Microsoft Excel 97 Standard Edition
Microsoft PowerPoint 2000 Standard Edition
Microsoft PowerPoint 2002 Standard Edition
Microsoft PowerPoint 97 Standard Edition
Microsoft Project 2000 Standard Edition
Microsoft Project 2002 Standard Edition
Microsoft Publisher 2002 Standard Edition
Microsoft Visio 2000 Enterprise Edition
Microsoft Visio 2000 Professional Edition
Microsoft Visio 2000 Standard Edition
Microsoft Visio 2000 Technical Edition
Microsoft Visio 2002 Professional Edition
Microsoft Visio 2002 Standard Edition
Microsoft Word 2000 Standard Edition
Microsoft Word 2002 Standard Edition
Microsoft Word 97 Standard Edition
Microsoft Word 98 Standard Edition
Microsoft Works Suite 2001
Microsoft Works Suite 2002
Microsoft Works Suite 2003
Microsoft Office 2000 Premium Edition
Microsoft Office 2000 Professional Edition
Microsoft Office 2000 Standard Edition
Microsoft Office XP Professional Edition
Microsoft Office XP Standard Edition
Microsoft Business Solutions–Great Plains Human Resources, when used with:
  Great Plains Dynamics 6.0
  Great Plains eEnterprise 6.0
Microsoft Great Plains Dynamics 7.0
Microsoft Great Plains eEnterprise 7.0
Microsoft Business Solutions–Great Plains 7.5
Microsoft Business Solutions-Solomon 4.5
Microsoft Great Plains Solomon IV 5.0

Keywords: 
kbofficexppresp3fix kboffice2000presp4fix kbsecvulnerability kbsecurity kbsecbulletin kbqfe kbfix kbbug KB822715

Copyright © 2004 - 2007 Gridview.org, Inc. All rights reserved. Powered by Smart Web Content Management System