Microsoft Knowledge Base Email Alertz

MS10-036: Vulnerability in COM validation in Microsoft Office could allow remote code execution

Search KbAlertz

Advanced Search

Receive Microsoft Knowledge Base articles by E-Mail?

Every night we scan the Microsoft Knowledge Base. If technologies you're interested in are updated, we'll send you an e-mail. You only get one e-mail a day, and only when new articles are added.

Click here to create a
FREE account
Already have an account?
[Click here to Login]











Microsoft Knowledge Base Article

This article contents is Microsoft Copyrighted material.
©2005-©2007 Microsoft Corporation. All rights reserved. Terms of Use | Trademarks

Article ID: 983235 - Last Review: June 24, 2010 - Revision: 4.0

MS10-036: Vulnerability in COM validation in Microsoft Office could allow remote code execution

On This Page

INTRODUCTION

Microsoft has released security bulletin MS10-036. To view the complete security bulletin, visit one of the following Microsoft websites:

How to obtain help and support for this security update

For home users, no-charge support is available by calling 1-866-PCSAFETY in the United States and Canada or by contacting your local Microsoft subsidiary. For more information about how to contact your local Microsoft subsidiary for support issues with security updates, visit the Microsoft International Support website:
http://support.microsoft.com/common/international.aspx?rdpath=4 (http://support.microsoft.com/common/international.aspx?rdpath=4)
North American customers can also obtain instant access to unlimited no-charge email support or to unlimited individual chat support by visiting the following Microsoft website:
http://support.microsoft.com/oas/default.aspx?&prid=7552 (http://support.microsoft.com/oas/default.aspx?&prid=7552)
For enterprise customers, support for security updates is available through your usual support contacts.

Resolution

We are providing a Microsoft Fix it solution for users on Windows XP systems that have Microsoft Office XP installed. Although this is not a code fix in the Office products themselves, the Microsoft Fix it solution provides similar protections against the vulnerability that is described in this bulletin. Although the risk to application compatibility is minimized, we recommend that users test this Microsoft Fix it solution before you distribute the solution widely. To determine the download location, use the Fix it buttons in this article.

What does the Fix it solution do?

The Fix it solution provides protections that are similar to the software updates that are offered in bulletin MS10-036. To do this, it adds extra validation of COM objects in Office documents. To offer this protection, the Fix it solution uses the IE kill-bit mechanism to help provide protection from malicious documents. The Fix it solution does not require a restart, and the Fix it solution can be deployed by using standard Microsoft deployment solutions. The Fix it solution applies to Office XP on Windows XP-based systems, and the Fix it solution addresses issues in Microsoft Word, Microsoft Excel, Microsoft PowerPoint, Microsoft Publisher, and Microsoft Visio.

Note This Fix it solution does not include the Office kill-bit override features. For more information about the Office kill-bit override features, click the following article number to view the following article in the Microsoft Knowledge Base:
983632  (http://kbalertz.com/Feedback.aspx?kbNumber=983632/en-US/ )  Security settings for ActiveX controls and OLE objects in Office 2003 and in the 2007 Office suite


Fix it for Office XP on a computer that is running Windows XP

To fix this problem automatically, click the Fix this problem link. Then click Run in the File Download dialog box, and follow the steps in this wizard.



Collapse this tableExpand this table
Enable FixDisable Fix
Fix this problem
Microsoft Fix it 50452
Fix this problem
Microsoft Fix it 50453


Note This wizard may be in English only. However, the automatic fix also works for other language versions of Windows.

Note If you are not on the computer that has the problem, you can save the automatic fix to a flash drive or to a CD, and then you can run it on the computer that has the problem.

MORE INFORMATION

More information about this security update

New functionality

This security update lets users control if and how ActiveX controls and OLE objects load with a Microsoft Office kill-bit list. For more information about this functionality, click the following article number to view the article in the Microsoft Knowledge Base:
983632  (http://kbalertz.com/Feedback.aspx?kbNumber=983632/en-US/ )  Security settings for ActiveX controls and OLE objects in Office 2003 and in the 2007 Office suite

Known issues and additional information about this security update

  • 982311  (http://kbalertz.com/Feedback.aspx?kbNumber=982311/en-US/ ) MS10-036: Description of the security update for Office 2003: June 8, 2010
  • 982312  (http://kbalertz.com/Feedback.aspx?kbNumber=982312/en-US/ )  MS10-036: Description of the security update for the 2007 Office system: June 8, 2010
  • 982133  (http://kbalertz.com/Feedback.aspx?kbNumber=982133/en-US/ ) MS10-036 and MS10-038: Description of the security update for Excel 2003: June 8, 2010
  • 982308  (http://kbalertz.com/Feedback.aspx?kbNumber=982308/en-US/ ) MS10-038 and MS10-036: Description of the security update for Excel 2007: June 8, 2010
  • 982157  (http://kbalertz.com/Feedback.aspx?kbNumber=982157/en-US/ ) MS10-036: Description of the security update for PowerPoint 2003: June 8, 2010
  • 982158  (http://kbalertz.com/Feedback.aspx?kbNumber=982158/en-US/ ) MS10-036: Description of the security update for PowerPoint 2007: June 8, 2010
  • 982122  (http://kbalertz.com/Feedback.aspx?kbNumber=982122/en-US/ ) MS10-036: Description of the security update for Publisher 2003: June 8, 2010
  • 982124  (http://kbalertz.com/Feedback.aspx?kbNumber=982124/en-US/ ) MS10-036: Description of the security update for Publisher 2007: June 8, 2010
  • 982126  (http://kbalertz.com/Feedback.aspx?kbNumber=982126/en-US/ ) MS10-036: Description of the security update for Visio 2003: June 8, 2010
  • 982127  (http://kbalertz.com/Feedback.aspx?kbNumber=982127/en-US/ ) MS10-036: Description of the security update for Visio 2007: June 8, 2010
  • 982134  (http://kbalertz.com/Feedback.aspx?kbNumber=982134/en-US/ ) MS10-036: Description of the security update for Word 2003: June 8, 2010
  • 982135  (http://kbalertz.com/Feedback.aspx?kbNumber=982135/en-US/ ) MS10-036: Description of the security update for Word 2007: June 8, 2010
  • 983632  (http://kbalertz.com/Feedback.aspx?kbNumber=983632/en-US/ )  Security Settings for ActiveX controls and OLE objects in Office 2003 and in the 2007 Office suite

Security update replacement information

This security update replaces the following security update:
  • 973965  (http://kbalertz.com/Feedback.aspx?kbNumber=973965/en-US/ ) MS09-060: Vulnerabilities in Microsoft Active Template Library (ATL) ActiveX Controls for Microsoft Office could allow remote code execution

APPLIES TO
  • Microsoft Office Ultimate 2007
  • Microsoft Office Enterprise 2007
  • Microsoft Office Professional 2007
  • Microsoft Office Professional Plus 2007
  • Microsoft Office Standard 2007
  • Microsoft Office Home and Student 2007
  • Microsoft Office Basic 2007
  • Microsoft Office Access 2007
  • Microsoft Office Excel 2007
  • Microsoft Office SharePoint Designer 2007
  • Microsoft Office OneNote 2007
  • Microsoft Office Outlook 2007
  • Microsoft Office PowerPoint 2007
  • Microsoft Office Publisher 2007
  • Microsoft Office Word 2007
  • Microsoft Office Project Professional 2007
  • Microsoft Office Project Standard 2007
  • Microsoft Office Visio Professional 2007
  • Microsoft Office Visio Standard 2007
  • Microsoft Office Basic Edition 2003
  • Microsoft Office Professional Edition 2003
  • Microsoft Office Small Business Edition 2003
  • Microsoft Office Standard Edition 2003
  • Microsoft Office Student and Teacher Edition 2003
  • Microsoft Office Access 2003
  • Microsoft Office Excel 2003
  • Microsoft Office FrontPage 2003
  • Microsoft Office OneNote 2003
  • Microsoft Office Outlook 2003
  • Microsoft Office PowerPoint 2003
  • Microsoft Office PowerPoint 2003 Viewer
  • Microsoft Office Publisher 2003
  • Microsoft Office Word 2003
  • Microsoft Office Project Professional 2003
  • Microsoft Office Project Standard 2003
  • Microsoft Office Visio Professional 2003
  • Microsoft Office Visio Standard 2003
Keywords: 
kbsecvulnerability kbsecurity kbsecbulletin kbfix kbexpertiseinter kbbug atdownload kbmsifixme kbfixme KB983235
       

Community Feedback System

Very often, it takes hours to solve a problem. Very often, you've looked high and low, and have tried a lot of solutions. When you finally found it, chances are, it was because someone else helped you. Here's your chance to give back. Use our community feedback tool to let others know what worked for you and what didn't.

Please also understand that the community feedback system is not warranted to be correct, it's simply a system that we've built to let people try and help each other. If something in a feedback response doesn't make sense to you, or you're not comfortable making changes that the feedback talks about (like registry edits), please consult a professional.

Thank you for using kbAlertz.com Feedback System.

-- Scott Cate