|
|
|
![]() |
Vulnerability Note VU#683612Microsoft Hyperlink Object Library buffer overflowOverviewA vulnerability in Microsoft Hyperlink Object Library may allow a remote attacker to execute arbitrary code on an affected system.I. DescriptionThe Hyperlink Object Library is a collection of application programming interfaces that provide functionality for handling hyperlinks. The Microsoft Hyperlink Object Library contains a buffer overflow vulnerability that may allow a remote attacker to execute arbitrary code. A remote attacker can exploit the vulnerability by crafting a malicious hyperlink embeded into a Microsoft Office file or e-mail message. If a user opens the malicious hyperlink, arbitrary code can be executed. Once the remote attacker has successfully exploited this vulnerability, they can gain the same user rights as the local user.Microsoft's bulletin states that the following Windows operating systems are affected by this vulnerability:
II. ImpactA remote attacker who can successfully convince a user to open an email message or Microsoft office file and click a link may be able to execute arbitrary code and gain control of the affected system.III. SolutionApply an update
Disabling the Hlink.dll registry key can protect the affected system from attempts to exploit this vulnerability. By disabling the Hlink.dll registry key, hyperlinks embedded in Microsoft Office documents cannot be edited or opened. Click Start, click Run, and type cacls %windir%\system32\hlink.dll /d everyone, and click ok Modify the Access Control List to disable the HLINK registry key Modifying the HLINK registry key in the Windows registry will help prevent the exploitation of this vulnerability. By modifying the HLINK registry key, hyperlinks embedded in Microsoft Office documents cannot be edited or opened. Please see the Microsoft Security Bulletin MS06-050 for further details and cautions regarding use of the Registry Editor. For Windows 2000 For Windows XP Service Pack 1 or Later Read e-mail messages in plain text Open only hyperlinks in Microsoft Office documents that come from trusted sources. Systems Affected
References
Thanks to Microsoft Security for reporting this vulnerability in Microsoft Security Bulletin MS06-050. Microsoft, in turn, thanks Steve Tai of CSC Australia Pty Limited for reporting the vulnerability to them. This document was written by Katie Washok.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||