Microsoft Office Publisher fails to properly validate Publisher documents, which may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system.
Microsoft Publisher is a desktop publishing application that is provided with some versions of Microsoft Office. Microsoft Publisher fails to properly handle malformed publisher (.pub) documents, which can result in an exploitable situation. The vulnerabilities include: Out-of-bounds array indexing, invalid pointer use, and memory corruption.
By convincing a user to open a specially crafted Publisher document, a remote, unauthenticated attacker could execute arbitrary code with the privileges of the user running Publisher.
Apply an update
These issues are addressed in Microsoft Security Bulletin MS11-091. Please also consider the following workarounds:
Use the Microsoft Enhanced Mitigation Experience Toolkit
This vulnerability was reported by Will Dormann of the CERT/CC.