Microsoft Office 2000 UA OUACTRL.OCX ActiveX Control Buffer Overflow Vulnerability
BID:24118
Info
Microsoft Office 2000 UA OUACTRL.OCX ActiveX Control Buffer Overflow Vulnerability
| Bugtraq ID: | 24118 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-2903 |
| Remote: | Yes |
| Local: | No |
| Published: | May 23 2007 12:00AM |
| Updated: | May 07 2015 05:37PM |
| Credit: | Shinnai is credited with the discovery of this issue. |
| Vulnerable: |
Microsoft Office 2000 Multilanguage Packs 0 Microsoft Office 2000 Korean Version Microsoft Office 2000 Japanese Version Microsoft Office 2000 Chinese Version Microsoft Office 2000 SP3 Microsoft Office 2000 SP1 Microsoft Office 2000 Microsoft Internet Explorer for Unix SP2 |
| Not Vulnerable: | |
Discussion
Microsoft Office 2000 UA OUACTRL.OCX ActiveX Control Buffer Overflow Vulnerability
Microsoft Office 2000 UA ActiveX Control is prone to a buffer-overflow vulnerability because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.
Microsoft Office 2000 UA ActiveX Control is prone to a buffer-overflow vulnerability because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.
Exploit / POC
Microsoft Office 2000 UA OUACTRL.OCX ActiveX Control Buffer Overflow Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to access a malicious webpage.
The following exploit code is available:
To exploit this issue, an attacker must entice an unsuspecting user to access a malicious webpage.
The following exploit code is available:
Solution / Fix
Microsoft Office 2000 UA OUACTRL.OCX ActiveX Control Buffer Overflow Vulnerability
Solution:
This issue is addressed in version 2.0 of the affected ActiveX control. Users are advised to update to the latest version of Microsoft Office 2000 with all appropriate patches.
Microsoft Office 2000
Microsoft Office 2000 SP1
Microsoft Office 2000 SP3
Microsoft Internet Explorer for Unix SP2
Solution:
This issue is addressed in version 2.0 of the affected ActiveX control. Users are advised to update to the latest version of Microsoft Office 2000 with all appropriate patches.
Microsoft Office 2000
-
Microsoft uactlsec.exe
http://www.microsoft.com/downloads/details.aspx?FamilyID=1e9388cc-76fa -40cf-a84a-6284f5a15533&DisplayLang=en
Microsoft Office 2000 SP1
-
Microsoft uactlsec.exe
http://www.microsoft.com/downloads/details.aspx?FamilyID=1e9388cc-76fa -40cf-a84a-6284f5a15533&DisplayLang=en
Microsoft Office 2000 SP3
-
Microsoft uactlsec.exe
http://www.microsoft.com/downloads/details.aspx?FamilyID=1e9388cc-76fa -40cf-a84a-6284f5a15533&DisplayLang=en
Microsoft Internet Explorer for Unix SP2
References
Microsoft Office 2000 UA OUACTRL.OCX ActiveX Control Buffer Overflow Vulnerability
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Microsoft Office Product Homepage (Microsoft)