[14212] in bugtraq

home help back first fref pref prev next nref lref last post

Re: @Stake Advisory: Microsoft Office 2000 ClipArt Vulnerablity

daemon@ATHENA.MIT.EDU (Weld Pond)
Thu Mar 9 00:24:52 2000

Mime-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Message-Id:  <Pine.BSO.4.21.0003080902570.29361-100000@0nus.l0pht.com>
Date:         Wed, 8 Mar 2000 09:13:05 -0500
Reply-To: Weld Pond <weld@L0PHT.COM>
From: Weld Pond <weld@L0PHT.COM>
X-To:         Dustin Miller <dmiller@WFDEVELOPMENT.COM>
To: BUGTRAQ@SECURITYFOCUS.COM
In-Reply-To:  <NNEAJNECJHKMLGIALPHDOEKMCDAA.dmiller@wfdevelopment.com>

On Tue, 7 Mar 2000, Dustin Miller wrote:

> This bug does not seem to affect Windows Millennium Edition Build 2476,
> oddly enough.  I do have Office 2000 Professional installed (retail
> version), and CAG alarms with an error, but no key was created.


From the advisory:

  This is proof of concept code only, but theoretically could be any
  executable code desired. This code works only on Windows 2000, but
  shifting around a few offsets yields code that works under Windows NT
  4.0 and Win9X.


Our proof of concept code will not give you a working test for the
vulnerability on NT 4.0, 95, 98, mill. edition or even all versions of Win
2000. Just because the key is not created don't think that you are not
vulnerable. As far as we know all versions of Clip Art Gallery shipped
with these products are effected: Office 2000, Home Publishing 2000, Works
2000, Picture It! 2000, and PhotoDraw? 2000 Version 1.

-weld

home help back first fref pref prev next nref lref last post