Short Name |
SMB:FILE:WEB-VIEW-DOC-SCR-INJ |
---|---|
Severity |
Major |
Recommended |
No |
Recommended Action |
Drop |
Category |
SMB |
Keywords |
Windows WebView Word Doc Script Injection |
Release Date |
2005/05/03 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects Word files with malicious metadata. An attacker could create a Word document with improper characters in the document metadata. If a user selects the file from a directory over SMB, it can allow the attacker to run scripts on the target computer. The file does not need to be opened for the script to run.
Exploiting this vulnerability enables the attacker to execute arbitrary code on the vulnerable system.