Microsoft Office Web Components ActiveX Control URL Parsing Remote Code Execution Vulnerability
BID:28135
Info
Microsoft Office Web Components ActiveX Control URL Parsing Remote Code Execution Vulnerability
| Bugtraq ID: | 28135 |
| Class: | Unknown |
| CVE: |
CVE-2006-4695 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 11 2008 12:00AM |
| Updated: | Mar 17 2008 03:51PM |
| Credit: | Chris Ries of VigilantMinds Inc. and Xiaohui of NCNIPC are credited with the discovery of this vulnerability. |
| Vulnerable: |
Microsoft Office Web Components 2000 0 |
| Not Vulnerable: | |
Discussion
Microsoft Office Web Components ActiveX Control URL Parsing Remote Code Execution Vulnerability
Microsoft Office Web Components is prone to a remote code-execution vulnerability.
An attacker may exploit this issue by enticing victims into opening a maliciously crafted HTML document.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts will likely result in denial-of-service conditions.
Microsoft Office Web Components is prone to a remote code-execution vulnerability.
An attacker may exploit this issue by enticing victims into opening a maliciously crafted HTML document.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts will likely result in denial-of-service conditions.
Exploit / POC
Microsoft Office Web Components ActiveX Control URL Parsing Remote Code Execution Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Microsoft Office Web Components ActiveX Control URL Parsing Remote Code Execution Vulnerability
Solution:
Microsoft has released an advisory and fixes to address this issue. Please see the references for more information.
Microsoft Office Web Components 2000 0
Solution:
Microsoft has released an advisory and fixes to address this issue. Please see the references for more information.
Microsoft Office Web Components 2000 0
-
Microsoft Security Update for Commerce Sever 2000 (KB941305)
http://www.microsoft.com/downloads/details.aspx?FamilyId=71DE76BA-B62C -4A7A-A78A-9317F5255B13 -
Microsoft Security Update For Microsoft BizTalk Server 2000 (KB939714)
http://www.microsoft.com/downloads/details.aspx?FamilyId=E0993E49C0A81 1D2973D00C04F79E4B3 -
Microsoft Security Update For Microsoft BizTalk Server 2002 (KB939714)
http://www.microsoft.com/downloads/details.aspx?FamilyId=12B7D09A92AB4 596996670799837D961 -
Microsoft Security Update For Microsoft Office 2000 Service Pack 3 (KB931660)
http://www.microsoft.com/downloads/details.aspx?FamilyId=806c654a-35e3 -4385-855a-4b803249bfcf -
Microsoft Security Update for Microsoft Office Web Components 2000 used in ISA Server 2000 Reporting
http://www.microsoft.com/downloads/details.aspx?FamilyId=526D87BD-C3DA -412E-8765-C15987AE9B01 -
Microsoft Security Update For Microsoft Office XP Service Pack 3 (KB931660)
http://www.microsoft.com/downloads/details.aspx?FamilyId=806c654a-35e3 -4385-855a-4b803249bfcf -
Microsoft Visual Studio .NET 2002 Service Pack 1 MSOWC.DLL Security Update
http://www.microsoft.com/downloads/details.aspx?FamilyId=D71B23FA-A873 -406D-BAD7-E38E565DEE39&displaylang=en -
Microsoft Visual Studio .NET 2003 Service Pack 1 MSOWC.DLL Security Update
http://www.microsoft.com/downloads/details.aspx?FamilyId=2FE10CCD-40CB -4090-B83D-EAE3D4ECA174&displaylang=en
References
Microsoft Office Web Components ActiveX Control URL Parsing Remote Code Execution Vulnerability
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Microsoft Office Product Homepage (Microsoft)
- Vulnerability Note VU#654577 (US-CERT)
- Microsoft Security Bulletin MS08-017 - Critical (Microsoft)