Microsoft Office Remote Code Execution Vulnerabilites (2489293)

Summary
This host is missing a critical security update according to Microsoft Bulletin MS11-023.
Impact
Successful exploitation could allow attackers to execute arbitrary code by tricking a user into opening a Word file from a network share or via a malicious Office document. Impact Level: System/Application
Solution
Run Windows Update and update the listed hotfixes or download and update mentioned hotfixes in the advisory from the below link, http://www.microsoft.com/technet/security/Bulletin/MS11-023.mspx
Insight
The flaws are caused by, - an error in a shared component that incorrectly restricts the path used for loading external libraries. - an error when dereferencing data structures within Office files containing graphic objects.
Affected
Microsoft Office XP Service Pack 3 Microsoft Office 2003 Service Pack 3 Microsoft Office 2007 Service Pack 2
References