TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

How the first Microsoft Office 2007 vulnerability was discovered

16 pointsby niklasbuschmann12 months ago

3 comments

neonate12 months ago
<a href="https:&#x2F;&#x2F;threadreaderapp.com&#x2F;thread&#x2F;1799457232607985698.html" rel="nofollow">https:&#x2F;&#x2F;threadreaderapp.com&#x2F;thread&#x2F;1799457232607985698.html</a>
SushiHippie12 months ago
TL;DR:<p>The author, working at eEye in 2006, found what seemed like a big zero-day in Office 2007, but it only worked with a debugger attached.<p>Not wanting to admit it wasn&#x27;t a real exploit, the eEye team pulled all-nighters for several days and found a real bug in Microsoft Publisher where SafeInt wasn&#x27;t enabled for a specific structure.<p>They found a valid exploit (CVE-2007-1754) which got patched in MS07-037. And he regrets causing Microsoft&#x27;s David LeBlanc to cut his vacation short.
netsharc12 months ago
That got obnoxious quickly when the &quot;Hey look everybody I&#x27;m drunk! Am I not the most awesome!&quot; tweets got mixed in...<p><a href="https:&#x2F;&#x2F;threadreaderapp.com&#x2F;thread&#x2F;1799457232607985698.html" rel="nofollow">https:&#x2F;&#x2F;threadreaderapp.com&#x2F;thread&#x2F;1799457232607985698.html</a>
评论 #40620353 未加载