Sploitus

Exploit for Microsoft Office Drawing Shapes memory corruption vulnerability

saint · 2008-04-04

Exploit Code

MARKDOWN31 lines
## https://sploitus.com/exploit?id=SAINT:E46A18CA9AB6F574026A15185F4F01B0
Added: 04/04/2008  
CVE: [CVE-2008-0118](<https://vulners.com/cve/CVE-2008-0118>)  
BID: [28146](<http://www.securityfocus.com/bid/28146>)  
OSVDB: [42709](<http://www.osvdb.org/42709>)  


### Background

[Microsoft Office](<http://office.microsoft.com>) is a package which provides word processing, spreadsheet, presentation, e-mail, and calendaring capabilities for Microsoft Windows workstations. 

### Problem

A memory corruption vulnerability allows command execution when a user opens a specially crafted Microsoft Office file. 

### Resolution

Apply the patch referenced in [Microsoft Security Bulletin 08-016](<http://www.microsoft.com/technet/security/bulletin/MS08-016.mspx>). 

### References

<http://www.microsoft.com/technet/security/bulletin/MS08-016.mspx>  


### Limitations

Exploit works on Microsoft PowerPoint 2002 SP3 with the patch KB934705. 

### Platforms

Windows