LandzDown Forum

Security => Security Alerts & Briefings => Topic started by: Corrine on March 24, 2014, 09:41:39 PM

Title: Security Advisory 2953095 for Microsoft Word 2010
Post by: Corrine on March 24, 2014, 09:41:39 PM
Microsoft released Security Advisory 2953095 (http://technet.microsoft.com/en-us/security/advisory/2953095) which relates to a vulnerability in Microsoft Word. At this time, Microsoft is aware of limited, targeted attacks directed at Microsoft Word 2010.

With the vulnerability, an attacker could cause remote code execution if someone was convinced to open a specially crafted Rich Text Format (RTF) file or a specially crafted mail in Microsoft Outlook while using Microsoft Word as the email viewer.

Links to the Microsoft Fix it solution, other recommendations and references are available in my blog post at Security Advisory 2953095 for Microsoft Word 2010 (http://securitygarden.blogspot.com/2014/03/security-advisory-2953095-for-microsoft.html).
Title: Re: Security Advisory 2953095 for Microsoft Word 2010
Post by: Corrine on April 08, 2014, 06:05:49 PM
If you installed the Fix it solution for the RTF vulnerability, after installing MS14-017, disable the Fix it so RTF files will render properly.

See my blog post at Microsoft Security Bulletin for April, 2014 (http://securitygarden.blogspot.com/2014/04/microsoft-security-bulletin-for-april.html) for a link to disable the Fix it solution.