CVE-2008-2463
Summary
| CVE | CVE-2008-2463 |
|---|---|
| State | PUBLISHED |
| Assigner | certcc |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-07-07 23:41:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snapshot Viewer and Microsoft Office Access 2000 through 2003, allows remote attackers to download arbitrary files to a client machine via a crafted HTML document or e-mail message, probably involving use of the SnapshotPath and CompressedPath properties and the PrintSnapshot method. NOTE: this can be leveraged for code execution by writing to a Startup folder. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Office Snapshot Viewer Activex | office2000 | All | All | All |
| Application | Microsoft | Office Snapshot Viewer Activex | office_2003 | All | All | All |
| Application | Microsoft | Office Snapshot Viewer Activex | office_xp | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| VU#837785 - Microsoft Office Snapshot Viewer ActiveX control race condition | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| marc.info | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Microsoft Access Snapshot Viewer ActiveX Control Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| US-CERT Technical Cyber Security Alert TA08-225A -- Microsoft Updates for Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| Your request has been blocked. This could be due to several reasons. | af854a3a-2127-422b-91ae-364da2661108 | www.microsoft.com | |
| Microsoft Access (Snapview.ocx 10.0.5529.0) ActiveX Remote Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| SecurityTracker.com Archives - Microsoft Access Snapshot Viewer ActiveX Control Lets Remote Users Download Files to Arbitrary Locations | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Snapshot Viewer for Microsoft Access ActiveX Control Arbitrary File Download Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| US-CERT Technical Cyber Security Alert TA08-189A -- Microsoft Office Snapshot Viewer ActiveX Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.