Microsoft Access Snapshot Viewer ActiveX Control Lets Remote Users Download Files to Arbitrary Locations
|
|
SecurityTracker Alert ID: 1020433 |
|
SecurityTracker URL: http://securitytracker.com/id/1020433
|
|
CVE Reference:
CVE-2008-2463
(Links to External Site)
|
Updated: Oct 14 2008
|
Original Entry Date: Jul 7 2008
|
Impact:
Execution of arbitrary code via network, Modification of system information, Modification of user information, User access via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 2000, 2002, 2003
|
Description:
A vulnerability was reported in Microsoft Access in the Snapshot Viewer ActiveX control. A remote user can cause arbitrary code to be downloaded and then later executed on the target user's system.
A remote user can create specially crafted HTML that, when loaded by the target user, will invoke the 'snapview.ocx' ActiveX control and download arbitrary files to arbitrary locations on the target user's system. The files can then be subsequently executed.
The CLSIDs of the vulnerable control are: F0E42D50-368C-11D0-AD81-00A0C90DC8D9, F0E42D60-368C-11D0-AD81-00A0C90DC8D9, and F2175210-368C-11D0-AD81-00A0C90DC8D9
Microsoft Office Access 2000, Microsoft Office Access 2002, and Microsoft Office Access 2003 are affected.
Snapshot Viewer for Microsoft Access is affected.
This vulnerability is being actively exploited.
|
Impact:
A remote user can create HTML that, when loaded by the target user, will download files to the target user's system. The files can then be later executed.
|
Solution:
The vendor has issued the following fixes:
Microsoft Office Access 2000 Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?familyid=54e4031d-298f-480c-88d5-0ad3b2b62ba9
Microsoft Office Access 2002 Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?familyid=34b655f8-1922-4246-94ca-ed381c3e3b13
Microsoft Office Access 2003 Service Pack 2 and Microsoft Office Access 2003 Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?familyid=fd698517-a504-427d-9e5f-fde8f102142c
Snapshot Viewer for Microsoft Access:
http://www.microsoft.com/downloads/details.aspx?FamilyId=7C22BB32-7CE3-4FF2-8366-BA2EB5135833
A restart is not required.
The Microsoft advisory is available at:
http://www.microsoft.com/technet/security/bulletin/ms08-041.mspx
|
Vendor URL: www.microsoft.com/technet/security/bulletin/ms08-041.mspx (Links to External Site)
|
Cause:
Access control error
|
Underlying OS:
Windows (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Mon, 7 Jul 2008 14:30:36 -0400
Subject: Microsoft Access
|
http://www.microsoft.com/technet/security/advisory/955179.mspx
CVE-2008-2463
|
|