PT-2010-2541 · Microsoft · Office Access+1

Publicado

2010-07-13

·

Atualizado

2018-10-12

·

CVE-2010-0814

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Office Access versions 2003 SP3 through 2007 SP2
Description A remote code execution issue exists due to improper interaction between the Microsoft Access Wizard Controls and Internet Explorer's memory-allocation approach during ActiveX control instantiation. This allows attackers to execute arbitrary code via a website referencing multiple ActiveX controls. An attacker who successfully exploits this issue could run arbitrary code as the logged-on user, potentially taking complete control of the affected system if the user has administrative rights.
Recommendations For Microsoft Office Access 2003 SP3, update to a version that is not affected by this issue. For Microsoft Office Access 2007 SP1 and SP2, update to a version that is not affected by this issue. As a temporary workaround, consider restricting the use of ActiveX controls in Internet Explorer to minimize the risk of exploitation.

Correção

RCE

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-0814
ZDI-10-117

Produtos afetados

Internet Explorer
Office Access