SecurityTracker.com
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 


Category:   Application (Database)  >   Microsoft Access Vendors:   Microsoft
Microsoft Access Snapshot Viewer ActiveX Control Lets Remote Users Download Files to Arbitrary Locations
SecurityTracker Alert ID:  1020433
SecurityTracker URL:  http://securitytracker.com/id/1020433
CVE Reference:   CVE-2008-2463   (Links to External Site)
Updated:  Oct 14 2008
Original Entry Date:  Jul 7 2008
Impact:   Execution of arbitrary code via network, Modification of system information, Modification of user information, User access via network
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): 2000, 2002, 2003
Description:   A vulnerability was reported in Microsoft Access in the Snapshot Viewer ActiveX control. A remote user can cause arbitrary code to be downloaded and then later executed on the target user's system.

A remote user can create specially crafted HTML that, when loaded by the target user, will invoke the 'snapview.ocx' ActiveX control and download arbitrary files to arbitrary locations on the target user's system. The files can then be subsequently executed.

The CLSIDs of the vulnerable control are: F0E42D50-368C-11D0-AD81-00A0C90DC8D9, F0E42D60-368C-11D0-AD81-00A0C90DC8D9, and F2175210-368C-11D0-AD81-00A0C90DC8D9

Microsoft Office Access 2000, Microsoft Office Access 2002, and Microsoft Office Access 2003 are affected.

Snapshot Viewer for Microsoft Access is affected.

This vulnerability is being actively exploited.

Impact:   A remote user can create HTML that, when loaded by the target user, will download files to the target user's system. The files can then be later executed.
Solution:   The vendor has issued the following fixes:

Microsoft Office Access 2000 Service Pack 3:

http://www.microsoft.com/downloads/details.aspx?familyid=54e4031d-298f-480c-88d5-0ad3b2b62ba9

Microsoft Office Access 2002 Service Pack 3:

http://www.microsoft.com/downloads/details.aspx?familyid=34b655f8-1922-4246-94ca-ed381c3e3b13

Microsoft Office Access 2003 Service Pack 2 and Microsoft Office Access 2003 Service Pack 3:

http://www.microsoft.com/downloads/details.aspx?familyid=fd698517-a504-427d-9e5f-fde8f102142c

Snapshot Viewer for Microsoft Access:

http://www.microsoft.com/downloads/details.aspx?FamilyId=7C22BB32-7CE3-4FF2-8366-BA2EB5135833

A restart is not required.

The Microsoft advisory is available at:

http://www.microsoft.com/technet/security/bulletin/ms08-041.mspx

Vendor URL:  www.microsoft.com/technet/security/bulletin/ms08-041.mspx (Links to External Site)
Cause:   Access control error
Underlying OS:  Windows (Any)

Message History:   This archive entry has one or more follow-up message(s) listed below.
Jul 8 2008 (US-CERT Issues Advisory) Microsoft Access Snapshot Viewer ActiveX Control Lets Remote Users Download Files to Arbitrary Locations
US-CERT has issued an advisory.



 Source Message Contents



[Original Message Not Available for Viewing]


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

This web site uses cookies for web analytics. Learn More

Copyright 2019, SecurityGlobal.net LLC