Vulnerability Note VU#361441
Microsoft Office Publisher contains multiple exploitable vulnerabilities
Microsoft Office Publisher fails to properly validate Publisher documents, which may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system.
Microsoft Publisher is a desktop publishing application that is provided with some versions of Microsoft Office. Microsoft Publisher fails to properly handle malformed publisher (.pub) documents, which can result in an exploitable situation. The vulnerabilities include: Out-of-bounds array indexing, invalid pointer use, and memory corruption.
By convincing a user to open a specially crafted Publisher document, a remote, unauthenticated attacker could execute arbitrary code with the privileges of the user running Publisher.
Apply an update
These issues are addressed in Microsoft Security Bulletin MS11-091. Please also consider the following workarounds:
Use the Microsoft Enhanced Mitigation Experience Toolkit
Vendor Information (Learn More)
|Vendor||Status||Date Notified||Date Updated|
|Microsoft Corporation||Affected||06 Dec 2010||13 Dec 2011|
CVSS Metrics (Learn More)
This vulnerability was reported by Will Dormann of the CERT/CC.
This document was written by Will Dormann.
- CVE IDs: CVE-2011-3410 CVE-2011-3411 CVE-2011-3412
- Date Public: 13 Dec 2011
- Date First Published: 13 Dec 2011
- Date Last Updated: 28 Mar 2012
- Severity Metric: 6.69
- Document Revision: 13
If you have feedback, comments, or additional information about this vulnerability, please send us email.