Microsoft Knowledge Base Email Alertz

KBAlertz.com: (822715) - Microsoft Visual Basic for Applications (VBA) is based on the Microsoft Visual Basic development system. Microsoft Office products include VBA and use it to perform certain functions. You can use VBA to build customized programs that are based on an...

Receive Microsoft Knowledge Base articles by E-Mail?

Every night we scan the Microsoft Knowledge Base. If technologies you're interested in are updated, we'll send you an e-mail. You only get one e-mail a day, and only when new articles are added.

Click here to create a
FREE account
Already have an account?
[Click here to Login]

Search KbAlertz

Advanced Search

Webmasters
Put kbAlertz on your website.
[ Click Here for more! ]





ASP.NET 3.5 Web Hosting with Windows 2008 and SQL 2008: Click Here!
Discount ASP.NET Hosting
ASP.NET 2.0 and 3.5
Windows2008 and SQL2008
US and UK Hosting
The ad says 3 - but KBAlertz referrals get
** SIX MONTHS FREE **


Bug Tracking Software
For bug tracking software or defect tracking software or issue tracking software, visit Axosoft.


Community Site



We Send hundreds of thousands of emails using ASP.NET Email



Expert Web Design & Graphic Design
Design44.com

ASP.NET 3.5 Web Hosting with Windows 2008 and SQL 2008: Click Here!
Discount ASP.NET Hosting
ASP.NET 2.0 and 3.5
Windows2008 and SQL2008
US and UK Hosting
The ad says 3 - but KBAlertz referrals get
** SIX MONTHS FREE **




Mentioned In








Microsoft Knowledge Base Article

This article contents is Microsoft Copyrighted material.
©2005-©2007 Microsoft Corporation. All rights reserved. Terms of Use | Trademarks




Article ID: 822715 - Last Review: December 4, 2007 - Revision: 3.10

MS03-037: Flaw in Visual Basic for Applications could allow arbitrary code execution

The information in this article affects the products that are listed in the "Applies To (http://support.microsoft.com/?id=822715#appliesto) " section of this article.

On This Page

SYMPTOMS

Microsoft Visual Basic for Applications (VBA) is based on the Microsoft Visual Basic development system. Microsoft Office products include VBA and use it to perform certain functions. You can use VBA to build customized programs that are based on an existing host program.

A flaw exists in the way VBA checks document properties passed to it when a document is opened by the host program. A buffer overrun exists which, if exploited successfully, could allow an attacker to execute code of their choice in the context of the logged on user.

For an attack to be successful, the logged on user would have to open a specially crafted document that was sent to them by an attacker. This document could be any type of document that supports VBA, such as a Microsoft Word document, a Microsoft Excel spreadsheet, or a Microsoft PowerPoint presentation. If Word is being used as the HTML e-mail editor for Microsoft Outlook, this document could be an e-mail message. However, the logged on user must reply to or forward the malicious e-mail message for the vulnerability to be exploited.

Mitigating factors
  • Logged-on users must open a document that is sent to them by an attacker for this vulnerability to be exploited.
  • If Word is being used as the HTML e-mail editor in Outlook, users must reply to or forward a malicious e-mail message that was sent to them by the attacker for this vulnerability to be exploited.
  • An attacker's code could only run with the same rights as the logged-on user. The specific privileges that the attacker could gain through this vulnerability would therefore depend on the privileges that are granted to the user who is logged on. Any limitations on the account of the user who is logged on , such as those applied through Group Policies, would also limit the actions of any arbitrary code that is executed by this vulnerability.

RESOLUTION

Security patch information

Download and installation information

If you are using any of the following programs, you should apply the VBA version of this patch:
  • Microsoft VBA 5.0
  • Microsoft VBA 6.0
  • Microsoft VBA 6.2
  • Microsoft VBA 6.3
  • Microsoft Access 97
  • Microsoft Excel 97
  • Microsoft PowerPoint 97
  • Microsoft Word 97
  • Microsoft Word 98(J)
  • Microsoft Works 2001
  • Microsoft Works 2002
  • Microsoft Works Suite 2003
  • Microsoft Business Solutions Great Plains 7.5
  • Microsoft Business Solutions Great Plains 7.0
  • Microsoft Business Solutions Great Plains 6.0
  • Microsoft Business Solutions Solomon IV 4.5
  • Microsoft Business Solutions Solomon IV 5.0
  • Microsoft Business Solutions Solomon IV 5.5
For more information about the Microsoft VBA patch, click the following article number to view the article in the Microsoft Knowledge Base:
822150  (http://kbalertz.com/Feedback.aspx?kbNumber=822150/ ) Availability of the Microsoft VBA security update for MS03-037
If you are using any of the following programs, you should apply the specific version of the patch for those products.
  • Microsoft Project 2000
  • Microsoft Project 2002
  • Microsoft Visio 2002
For more information about these security patches, click the following article numbers to view the articles in the Microsoft Knowledge Base:
822211  (http://kbalertz.com/Feedback.aspx?kbNumber=822211/ ) Description of the Microsoft Project 2002 security patch: September 3, 2003
822212  (http://kbalertz.com/Feedback.aspx?kbNumber=822212/ ) Description of the Visio 2002 security patch: September 3, 2003
If you are using any of the following programs, you should apply the specific version of the patch for those products.
  • Microsoft Office 2000
  • Microsoft Office XP (including Microsoft Publisher 2002)
For more information about these security patches, click the following article numbers to view the articles in the Microsoft Knowledge Base:
822036  (http://kbalertz.com/Feedback.aspx?kbNumber=822036/ ) Description of the Office XP security patch: September 3, 2003
822035  (http://kbalertz.com/Feedback.aspx?kbNumber=822035/ ) Description of the Office 2000 security patch: September 3, 2003

Removal information

You cannot remove this patch.

Patch replacement information

This patch does not replace any other hotfixes.

REFERENCES

For more information about these vulnerabilities, visit the following Microsoft Web site:
http://www.microsoft.com/technet/security/bulletin/MS03-037.mspx (http://www.microsoft.com/technet/security/bulletin/MS03-037.mspx)

APPLIES TO
  • Microsoft Visual Basic for Applications (VBA) Software Development Kit (SDK) 5.0
  • Microsoft Access 97 Standard Edition
  • Microsoft Access 2000 Standard Edition
  • Microsoft Access 2002 Standard Edition
  • Microsoft Excel 2000 Standard Edition
  • Microsoft Excel 2002 Standard Edition
  • Microsoft Excel 97 Standard Edition
  • Microsoft PowerPoint 2000 Standard Edition
  • Microsoft PowerPoint 2002 Standard Edition
  • Microsoft PowerPoint 97 Standard Edition
  • Microsoft Project 2000 Standard Edition
  • Microsoft Project 2002 Standard Edition
  • Microsoft Publisher 2002 Standard Edition
  • Microsoft Visio 2000 Enterprise Edition
  • Microsoft Visio 2000 Professional Edition
  • Microsoft Visio 2000 Standard Edition
  • Microsoft Visio 2000 Technical Edition
  • Microsoft Visio 2002 Professional Edition
  • Microsoft Visio 2002 Standard Edition
  • Microsoft Word 2000 Standard Edition
  • Microsoft Word 2002 Standard Edition
  • Microsoft Word 97 Standard Edition
  • Microsoft Word 98 Standard Edition
  • Microsoft Works Suite 2001
  • Microsoft Works Suite 2002
  • Microsoft Works Suite 2003
  • Microsoft Office 2000 Premium Edition
  • Microsoft Office 2000 Professional Edition
  • Microsoft Office 2000 Standard Edition
  • Microsoft Office XP Professional Edition
  • Microsoft Office XP Standard Edition
  • Microsoft Business Solutions–Great Plains Human Resources, when used with:
    • Great Plains Dynamics 6.0
    • Great Plains eEnterprise 6.0
  • Microsoft Great Plains Dynamics 7.0
  • Microsoft Great Plains eEnterprise 7.0
  • Microsoft Business Solutions–Great Plains 7.5
  • Microsoft Great Plains Solomon IV 5.0
Keywords: 
kbofficexppresp3fix kboffice2000presp4fix kbsecvulnerability kbsecurity kbsecbulletin kbqfe kbfix kbbug KB822715
       

Community Feedback System

Very often, it takes hours to solve a problem. Very often, you've looked high and low, and have tried a lot of solutions. When you finally found it, chances are, it was because someone else helped you. Here's your chance to give back. Use our community feedback tool to let others know what worked for you and what didn't.

Please also understand that the community feedback system is not warranted to be correct, it's simply a system that we've built to let people try and help each other. If something in a feedback response doesn't make sense to you, or you're not comfortable making changes that the feedback talks about (like registry edits), please consult a professional.

Thank you for using kbAlertz.com Feedback System.

-- Scott Cate

Be the first to leave feedback, to help others about this knowledge base article.

(Optional) Name

(Optional) Public URL Or Email

Comments
No HTML -- Text Only Please