SecurityTracker.com
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 


Category:   Application (Generic)  >   Microsoft Access Vendors:   Microsoft
Microsoft Office Access ActiveX Controls Let Remote Users Execute Arbitrary Code
SecurityTracker Alert ID:  1024188
SecurityTracker URL:  http://securitytracker.com/id/1024188
CVE Reference:   CVE-2010-0814, CVE-2010-1881   (Links to External Site)
Date:  Jul 13 2010
Impact:   Execution of arbitrary code via network, User access via network
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): 2003 SP3, 2007 SP2; and prior service packs
Description:   Two vulnerabilities were reported in Microsoft Office Access. A remote user can cause arbitrary code to be executed on the target user's system.

A remote user can create specially crafted HTML that, when loaded by the target user, will invoke ACCWIZ.dll (Microsoft Access Wizard Controls) and trigger a memory allocation error and execute arbitrary code on the target system [CVE-2010-0814]. The code will run with the privileges of the target user.

An anonymous researcher reported this vulnerability via TippingPoint.

A remote user can create specially crafted HTML that, when loaded by the target user, will invoke ACCWIZ.dll and trigger a memory corruption error in the FieldList ActiveX control and execute arbitrary code on the target system [CVE-2010-1881]. The code will run with the privileges of the target user.

Robert Freeman of IBM ISS X-Force reported this vulnerability.

Impact:   A remote user can create HTML that, when loaded by the target user, will execute arbitrary code on the target user's system.
Solution:   The vendor has issued the following fixes:

Microsoft Office 2003 Service Pack 3, Microsoft Office Access 2003 Service Pack 3:

http://www.microsoft.com/downloads/details.aspx?familyid=93768ac6-e6d7-4175-a6e3-666210494678

2007 Microsoft Office System Service Pack 1 and 2007 Microsoft Office System Service Pack 2, Microsoft Office Access 2007 Service Pack 1 and Microsoft Office Access 2007 Service Pack 2:

http://www.microsoft.com/downloads/details.aspx?familyid=af2862e2-da37-4cbe-8974-e517eb666f14

A restart may be required.

The Microsoft advisory is available at:

http://www.microsoft.com/technet/security/bulletin/ms10-044.mspx

Vendor URL:  www.microsoft.com/technet/security/bulletin/ms10-044.mspx (Links to External Site)
Cause:   Access control error
Underlying OS:  Windows (Any)

Message History:   None.


 Source Message Contents



[Original Message Not Available for Viewing]


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

This web site uses cookies for web analytics. Learn More

Copyright 2021, SecurityGlobal.net LLC