PT-2007-3907 · Microsoft · Office Viewer Ocx Activex Control

Publicado

2007-05-09

·

Atualizado

2017-07-29

·

CVE-2007-2588

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Office Viewer OCX ActiveX control (oa.ocx) version 3.2
Description The issue is related to multiple buffer overflows in the Office Viewer OCX ActiveX control. This can be exploited by remote attackers who send a long argument to certain functions, potentially causing a denial of service or possibly allowing the execution of arbitrary code. The affected functions include HttpDownloadFile(), Open(), OpenWebFile(), DoOleCommand(), FTPDownloadFile(), FTPUploadFile(), HttpUploadFile(), Save(), and SaveWebFile().
Recommendations For Office Viewer OCX ActiveX control (oa.ocx) version 3.2, consider disabling the affected functions until a patch is available. Restrict access to the oa.ocx control to minimize the risk of exploitation. Avoid using long arguments in the affected functions to prevent potential buffer overflows.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-2588

Produtos afetados

Office Viewer Ocx Activex Control