PT-2010-3505 · Microsoft · Office Access+2

Published

2010-07-14

·

Updated

2018-10-12

·

CVE-2010-1881

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Office Access 2003 SP3
Description A remote code execution issue exists due to improper interaction between the FieldList ActiveX control in Microsoft Access Wizard Controls and the memory-access approach used by Internet Explorer and Office. This allows attackers to execute arbitrary code or cause a denial of service via an HTML document referencing this control along with crafted persistent storage data. An attacker could run arbitrary code as the logged-on user, potentially taking complete control of the affected system if the user has administrative rights.
Recommendations For Microsoft Office Access 2003 SP3, consider disabling the FieldList ActiveX control as a temporary workaround until a patch is available. Restrict access to crafted HTML documents that could reference this control to minimize the risk of exploitation.

Fix

RCE

DoS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-1881

Affected Products

Internet Explorer
Access Wizard Controls
Office Access