Risk: High
Two new vulnerabilities have been reported in various flavours of Microsoft Word, which can be exploited to compromise a user's system.
The vulnerabilities are caused due to boundary errors within the parsing of document files. This can be exploited to cause buffer overflows by tricking a user into opening a specially crafted Word document.
Successful exploitation allows execution of arbitrary code with the privileges of the user running Microsoft Word.
If a user is logged on with administrative privileges, an attacker who successfully exploited this vulnerability could take complete control of an affected system, including installing programs; viewing, changing, or deleting data; or creating new accounts with full privileges. Users whose accounts are configured to have fewer privileges on the system would be at less risk than users who operate with administrative privileges.