Microsoft Forms 2.0 ActiveX Control Memory Access Violation Denial of Service Vulnerabilities
BID:26414
Info
Microsoft Forms 2.0 ActiveX Control Memory Access Violation Denial of Service Vulnerabilities
| Bugtraq ID: | 26414 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 12 2007 12:00AM |
| Updated: | Nov 13 2007 12:25PM |
| Credit: | Elazar Broad is credited with the discovery of this issue. |
| Vulnerable: |
Microsoft Forms ActiveX Control 2.0 |
| Not Vulnerable: | |
Discussion
Microsoft Forms 2.0 ActiveX Control Memory Access Violation Denial of Service Vulnerabilities
Microsoft Forms 2.0 ActiveX Control is prone to multiple memory-access violation denial-of-service vulnerabilities.
Attackers can exploit these issues to crash Internet Explorer and deny service to legitimate users.
Note: Forms 2.0 ActiveX is distributed with any application that includes Visual Basic for Applications 5.0.
Microsoft Forms 2.0 ActiveX Control is prone to multiple memory-access violation denial-of-service vulnerabilities.
Attackers can exploit these issues to crash Internet Explorer and deny service to legitimate users.
Note: Forms 2.0 ActiveX is distributed with any application that includes Visual Basic for Applications 5.0.
Exploit / POC
Microsoft Forms 2.0 ActiveX Control Memory Access Violation Denial of Service Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting user to use the affected application to view a maliciously crafted webpage.
The following example exploit code is available:
To exploit these issues, an attacker must entice an unsuspecting user to use the affected application to view a maliciously crafted webpage.
The following example exploit code is available:
Solution / Fix
Microsoft Forms 2.0 ActiveX Control Memory Access Violation Denial of Service Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Microsoft Forms 2.0 ActiveX Control Memory Access Violation Denial of Service Vulnerabilities
References:
References:
- Microsoft Homepage (Microsoft)