HTTP: Microsoft Office Malformed GIF File Parser Overflow

This signature detects attempts to exploit a known vulnerability in the Microsoft Office GIF file parser. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the user.

Extended Description

Microsoft Office is prone to a remote code-execution vulnerability when handling a malformed GIF file. The issue occurs when an Office application such as Excel, Word, or PowerPoint tries to open a malformed GIF file. An attacker could exploit this vulnerability to corrupt memory and subsequently execute malicious code in the context of the user running the affected application.

Affected Products

Microsoft office_2003

References

BugTraq: 18915

CVE: CVE-2006-0007

Short Name
HTTP:STC:IMG:MS-OFFICE-GIF
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2006-0007 File GIF Malformed Microsoft Office Overflow Parser bid:18915
Release Date
10/04/2010
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Microsoft

CVSS Score

9.3

Found a potential security threat?