Jump to content
YOUR-AD-HERE
HOSTING
TOOLS
992Proxy

Locked Microsoft Word Local Machine Zone Remote Code Execution Vulnerability


sniffer

Recommended Posts

Exploit Title: Microsoft Word Local Machine Zone Remote Code Execution Vulnerability

Date: July 15th, 2015

Exploit Author: Eduardo Braun Prado

Vendor Homepage :

This is the hidden content, please

Version: 2007

Tested on: Microsoft Windows XP, 2003, Vista, 2008, 7, 8, 8.1

CVE: CVE-2015-0097

 

Original Advisory:

This is the hidden content, please

 

Microsoft Word, Excel and Powerpoint 2007 contains a remote code execution vulnerability because it is possible to reference documents such as Works document (.wps) as HTML. It will process HTML and script code in the context of the local machine zone of Internet Explorer which leads to arbitrary code execution. By persuading users into opening eg. specially crafted .WPS, ".doc ", ".RTF " (with a space at the end) it is possible to triggerthe vulnerability and run arbitrary code in the context of the logged on Windows user.

 

Exploit code here :

 

This is the hidden content, please

This is the hidden content, please

 

 

This is the hidden content, please

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.