|
|
|
![]() |
Vulnerability Note VU#703936Microsoft Object Packager fails to properly display file typesOverviewThe Microsoft Object Packager fails to properly display the file types. This vulnerability may allow a remote, unauthenticated attacker execute arbitrary code on a vulnerable system.I. DescriptionAccording to Microsoft:Object Packager is a tool you can use to create a package that you can insert into a file.
II. ImpactAttackers can conceal the types of objects embedded within files, possibly misleading users into executing arbitrary code.III. SolutionApply an updateThis vulnerability is addressed in Microsoft Security Bulletin MS06-065. Do not open files originating from unfamiliar or unexpected sources, including those received as email attachments or hosted on a web site. For more information, please see Using Caution with Email Attachments.
References
This issue was reported in Microsoft Security Bulletin MS06-065. Microsoft credits Andreas Sandblad of Secunia Research for reporting this vulnerability. This document was written by Jeff Gennari.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||