Vulnerabilities Affecting Microsoft Word and the Microsoft Jet Database Engine

May 13th, 2008

The Sourcefire VRT is aware of vulnerabilities affecting Microsoft Word and the Microsoft Jet Database Engine.

Details: 

Microsoft Security Bulletin (MS08-026):
Microsoft Word contains a programming error that may allow a remote attacker to execute code on a vulnerable system. The problem occurs when Word parses a file that includes a malformed CSS value.
A rule to detect attacks targeting this vulnerability is included in this release and is identified with GID 3 SID 13790.
Microsoft Security Bulletin (MS08-028):
The Microsoft Jet Database Engine contains a programming error that may allow a remote attacker to execute code on an affected system.
Previously released rules are able to detect attacks targeting this vulnerability and are identified with GID 3 and SIDs 13626, 13629, 13630 and 13633.
The Sourcefire VRT has also added multiple rules in the web-client and specific-threats categories to provide coverage for emerging threats.

For Assistance