Workaround for Multiple Microsoft Visio Memory Corruption Vulnerabilities (MS10-028)
| Check Point Reference: | SBP-2010-14 | |
| Date Published: | ||
| Severity: | ||
| Source: | Microsoft Security Bulletin MS10-028 | |
| Industry Reference(s): | CVE-2010-0254 CVE-2010-0256 CVE-2010-0095 CVE-2010-0096 CVE-2010-0097 |
|
| Protection Provided by: |
Security Gateway
|
|
| Who is Vulnerable? Microsoft Office Visio 2002 SP2 Microsoft Office Visio 2003 SP3 Microsoft Office Visio 2007 SP1 | ||
| Vulnerability Description Multiple remote code execution vulnerabilities have been identified in Microsoft Visio. Microsoft Visio is a diagram creation software for Microsoft Windows. A remote attacker can exploit these vulnerabilities via a specially crafted Visio file. Successful exploitation may allow execution of arbitrary code on a vulnerable system. |
||
|
Update/Patch Available Apply patches: Microsoft Security Bulletin MS10-028 |
|
|
Vulnerability Details The vulnerabilities are due to the way Microsoft Office Visio handles memory when opening Visio files: CVE-2010-0254 - The vulnerability exists in the way that Microsoft Office Visio validates attributes when handling specially crafted Visio files. CVE-2010-0256 - The vulnerability exists in the way that Microsoft Office Visio calculates indexes when handling specially crafted Visio files. A remote attacker could trigger this flaw by convincing a victim to open a specially crafted Visio file in legacy format. Successful exploitation of this issue may corrupt system memory, allowing execution of arbitrary code on a vulnerable system. |
Protection Overview
This protection detects and blocks the transferring of legacy Office Visio files over HTTP.
Since the protection offered in this advisory may block access to legitimate files, users are advised to use this protection as a workaround till all systems are patched.
In order for the protection to be activated, update your Security Gateway/VPN-1 product to the latest IPS/SmartDefense update. For information on how to update IPS/SmartDefense, go to SBP-2006-05, Protection tab and select the version of your choice.
To configure the defense, select your product from the list below and follow the related protection steps.