HTTP: Microsoft Office PNG Image Filter Code Execution

This signature detects attempts to exploit a known vulnerability against Microsoft Office. A successful attack can lead to arbitrary code execution.

Extended Description

Microsoft Office is prone to a remote code-execution vulnerability when handling a malformed PNG graphic file. The issue occurs when an Office application such as Excel, Word, or PowerPoint tries to open a malformed PNG graphic file. An attacker could exploit this vulnerability to cause memory corruption and subsequently to execute malicious code in the context of the user running the affected application.

Affected Products

Microsoft office_2003

References

BugTraq: 18913

CVE: CVE-2006-0033

Short Name
HTTP:STC:DL:MS-PNG-IMG-CE
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2006-0033 Code Execution Filter Image Microsoft Office PNG bid:18913
Release Date
12/19/2012
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Microsoft

CVSS Score

9.3

Found a potential security threat?