SB2016101131 - Multiple vulnerabilities in Apache OpenOffice
Published: October 11, 2016
Security Bulletin ID
SB2016101131
Severity
High
Patch available
YES
Number of vulnerabilities
2
Exploitation vector
Remote access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Privilege escalation (CVE-ID: CVE-2016-6803)
The vulnerability allows a local user to execute arbitrary code with elevated privileges on the target system.The weakness is caused by performing of improper operations for files that use a search path containing an unquoted element. Attackers can exploit the vulnerability by tricking the victim to execute arbitrary file downloaded by trojan horse application.
Successful exploitation of the vulnerability results in arbitrary code execution on the vulnerable system that may lead to complete system compromise.
2) Insecure DLL loading (CVE-ID: CVE-2016-6804)
The vulnerability allows a remote attacker to execute arbitrary code with elevated privileges on the target system.The weakness is caused by improper search path operations by the affected software. By tricking the victim to save and run a malicious file, disguised as a DLL, attackers can execute arbitrary code.
Successful exploitation of the vulnerability results in arbitrary code execution on the vulnerable system that may lead to complete system compromise.
Remediation
Install update from vendor's website.