SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com






Category:   Application (Database)  >   Microsoft Access Vendors:   Microsoft
Microsoft Access Snapshot Viewer ActiveX Control Lets Remote Users Download Files to Arbitrary Locations
SecurityTracker Alert ID:  1020433
SecurityTracker URL:  http://securitytracker.com/id/1020433
CVE Reference:   CVE-2008-2463   (Links to External Site)
Updated:  Oct 14 2008
Original Entry Date:  Jul 7 2008
Impact:   Execution of arbitrary code via network, Modification of system information, Modification of user information, User access via network
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): 2000, 2002, 2003
Description:   A vulnerability was reported in Microsoft Access in the Snapshot Viewer ActiveX control. A remote user can cause arbitrary code to be downloaded and then later executed on the target user's system.

A remote user can create specially crafted HTML that, when loaded by the target user, will invoke the 'snapview.ocx' ActiveX control and download arbitrary files to arbitrary locations on the target user's system. The files can then be subsequently executed.

The CLSIDs of the vulnerable control are: F0E42D50-368C-11D0-AD81-00A0C90DC8D9, F0E42D60-368C-11D0-AD81-00A0C90DC8D9, and F2175210-368C-11D0-AD81-00A0C90DC8D9

Microsoft Office Access 2000, Microsoft Office Access 2002, and Microsoft Office Access 2003 are affected.

Snapshot Viewer for Microsoft Access is affected.

This vulnerability is being actively exploited.

Impact:   A remote user can create HTML that, when loaded by the target user, will download files to the target user's system. The files can then be later executed.
Solution:   The vendor has issued the following fixes:

Microsoft Office Access 2000 Service Pack 3:

http://www.microsoft.com/downloads/details.aspx?familyid=54e4031d-298f-480c-88d5-0ad3b2b62ba9

Microsoft Office Access 2002 Service Pack 3:

http://www.microsoft.com/downloads/details.aspx?familyid=34b655f8-1922-4246-94ca-ed381c3e3b13

Microsoft Office Access 2003 Service Pack 2 and Microsoft Office Access 2003 Service Pack 3:

http://www.microsoft.com/downloads/details.aspx?familyid=fd698517-a504-427d-9e5f-fde8f102142c

Snapshot Viewer for Microsoft Access:

http://www.microsoft.com/downloads/details.aspx?FamilyId=7C22BB32-7CE3-4FF2-8366-BA2EB5135833

A restart is not required.

The Microsoft advisory is available at:

http://www.microsoft.com/technet/security/bulletin/ms08-041.mspx

Vendor URL:  www.microsoft.com/technet/security/bulletin/ms08-041.mspx (Links to External Site)
Cause:   Access control error
Underlying OS:   Windows (Any)

Message History:   This archive entry has one or more follow-up message(s) listed below.
Jul 8 2008 (US-CERT Issues Advisory) Microsoft Access Snapshot Viewer ActiveX Control Lets Remote Users Download Files to Arbitrary Locations   (US-CERT Technical Alerts <technical-alerts@us-cert.gov>)
US-CERT has issued an advisory.



 Source Message Contents

Date:  Mon, 7 Jul 2008 14:30:36 -0400
Subject:  Microsoft Access


http://www.microsoft.com/technet/security/advisory/955179.mspx

CVE-2008-2463
 
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

Copyright 2013, SecurityGlobal.net LLC