Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:STC:DL:XLS-FRTWRAPPER1

Severity

Medium

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

Microsoft Excel FRTWrapper Record Buffer Overflow1

Release Date

2015/09/30

Update Number

2541

Supported Platforms

idp-4.1+, isg-3.5.141421+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: Microsoft Excel FRTWrapper Record Buffer Overflow1


This signature detects attempts to exploit a known buffer overflow vulnerability in Microsoft Excel product. It is specifically due to improper parsing of Excel documents containing specially crafted FRTWrapper records. Remote attackers can exploit this by enticing target users to open a crafted Excel file, potentially causing arbitrary code to be injected and executed in the security context of the current user. In a successful attack, where arbitrary code is injected and executed on the target machine, the behavior of the target is dependent on the intention of the malicious code. In an unsuccessful attack, the vulnerable application can terminate as a result of invalid memory access. If unexpected termination of the application is the sole result of an attack, there is no impact to the overall operation of the target host. It is, however, possible to lose all unsaved data due to the abnormal termination.

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out