[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2008-2463Date: (C)2008-07-07   (M)2023-12-22


The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snapshot Viewer and Microsoft Office Access 2000 through 2003, allows remote attackers to download arbitrary files to a client machine via a crafted HTML document or e-mail message, probably involving use of the SnapshotPath and CompressedPath properties and the PrintSnapshot method. NOTE: this can be leveraged for code execution by writing to a Startup folder.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.8
Exploit Score: 8.6
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECTRACK-1020433
BID-30114
SECUNIA-30883
EXPLOIT-DB-6124
ADV-2008-2012
HPSBST02360
TA08-189A
TA08-225A
VU#837785
http://www.microsoft.com/technet/security/advisory/955179.mspx
microsoft-snapshotviewer-code-execution(43613)
oval:org.mitre.oval:def:6120

CWE    1
CWE-94
OVAL    2
oval:org.mitre.oval:def:6120
oval:org.secpod.oval:def:2665

© SecPod Technologies