Article ID: 827103 - View products that this article applies to.
With the converters that Microsoft Office provides, users can import and edit files that use formats that are not native to Office. These converters are available as part of the default installation of Office and are also available separately in the Microsoft Office Converter Pack. These converters can be useful to organizations that use Office in a mixed environment with earlier versions of Office and other programs, including Office for the Macintosh and third-party productivity programs.
There is a flaw in the way that the Microsoft WordPerfect converter handles Corel WordPerfect documents. A security vulnerability exists because the converter does not correctly validate certain parameters when it opens a WordPerfect document; this results in an unchecked buffer. Therefore, an attacker could craft a malicious WordPerfect document that could allow code of their choice to be executed if a program that uses the WordPerfect converter opened the document. Microsoft Word and Microsoft PowerPoint (which are part of the Office suite), FrontPage (which is available as part of the Office suite or separately), Publisher, and Microsoft Works Suite can all use the Microsoft Office WordPerfect converter.
The vulnerability can be exploited only by an attacker who persuades a user to open a malicious WordPerfect document. An attacker cannot force a user to open a malicious document; an attacker cannot use this vulnerability to trigger an attack automatically in e-mail.
Security Patch Information
Download and Installation InformationIf you are using any of the following programs
(http://support.microsoft.com/kb/824938/ )Overview of the Office XP WordPerfect 5.x Converter Security Patch: September 3, 2003
If you are using any of the following programs
(http://support.microsoft.com/kb/824993/ )Overview of the Office 2000 WordPerfect 5.x Converter Security Patch: September 3, 2003
If you are running either of the following programs
(http://support.microsoft.com/kb/827656/ )Overview of the Office 97 WordPerfect 5.x Converter Security Patch: September 3, 2003
You cannot remove this patch.
Patch Replacement Information
This patch does not replace any other security patches.
For more information about these vulnerabilities, visit the following Microsoft Web site:
Article ID: 827103 - Last Review: November 1, 2004 - Revision: 4.2