PT-2010-3505 · Microsoft · Office Access+2
Published
2010-07-14
·
Updated
2018-10-12
·
CVE-2010-1881
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Office Access 2003 SP3
Description
A remote code execution issue exists due to improper interaction between the FieldList ActiveX control in Microsoft Access Wizard Controls and the memory-access approach used by Internet Explorer and Office. This allows attackers to execute arbitrary code or cause a denial of service via an HTML document referencing this control along with crafted persistent storage data. An attacker could run arbitrary code as the logged-on user, potentially taking complete control of the affected system if the user has administrative rights.
Recommendations
For Microsoft Office Access 2003 SP3, consider disabling the FieldList ActiveX control as a temporary workaround until a patch is available. Restrict access to crafted HTML documents that could reference this control to minimize the risk of exploitation.
Fix
RCE
DoS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Internet Explorer
Access Wizard Controls
Office Access