SMB: Windows WebView Word Doc Script Injection

This signature detects Word files with malicious metadata. An attacker could create a Word document with improper characters in the document metadata. If a user selects the file from a directory over SMB, it can allow the attacker to run scripts on the target computer. The file does not need to be opened for the script to run.

Extended Description

Exploiting this vulnerability enables the attacker to execute arbitrary code on the vulnerable system.

Short Name
SMB:FILE:WEB-VIEW-DOC-SCR-INJ
Severity
Major
Recommended
False
Recommended Action
Drop
Category
SMB
Keywords
CVE-2005-0557 Doc Injection Script WebView Windows Word
Release Date
05/03/2005
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown

Found a potential security threat?