PT-2007-3907 · Microsoft · Office Viewer Ocx Activex Control
Publicado
2007-05-09
·
Atualizado
2017-07-29
·
CVE-2007-2588
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Office Viewer OCX ActiveX control (oa.ocx) version 3.2
Description
The issue is related to multiple buffer overflows in the Office Viewer OCX ActiveX control. This can be exploited by remote attackers who send a long argument to certain functions, potentially causing a denial of service or possibly allowing the execution of arbitrary code. The affected functions include
HttpDownloadFile(), Open(), OpenWebFile(), DoOleCommand(), FTPDownloadFile(), FTPUploadFile(), HttpUploadFile(), Save(), and SaveWebFile().Recommendations
For Office Viewer OCX ActiveX control (oa.ocx) version 3.2, consider disabling the affected functions until a patch is available. Restrict access to the
oa.ocx control to minimize the risk of exploitation. Avoid using long arguments in the affected functions to prevent potential buffer overflows.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Office Viewer Ocx Activex Control