Snapshot Viewer for Microsoft Access ActiveX Control Arbitrary File Download Vulnerability
BID:30114
Info
Snapshot Viewer for Microsoft Access ActiveX Control Arbitrary File Download Vulnerability
| Bugtraq ID: | 30114 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-2463 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 07 2008 12:00AM |
| Updated: | Oct 15 2008 03:17AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Microsoft Snapshot Viewer for Microsoft Access 0 Microsoft Access 2003 SP3 Microsoft Access 2003 SP2 Microsoft Access 2003 Microsoft Access 2002 SP3 Microsoft Access 2002 SP2 Microsoft Access 2002 SP1 Microsoft Access 2002 Microsoft Access 2000 SR1 Microsoft Access 2000 SP3 Microsoft Access 2000 SP2 Microsoft Access 2000 |
| Not Vulnerable: | |
Discussion
Snapshot Viewer for Microsoft Access ActiveX Control Arbitrary File Download Vulnerability
Snapshot Viewer for Microsoft Access is prone to a vulnerability that can cause malicious files to be downloaded and saved to arbitrary locations on an affected computer.
Attackers may exploit this issue to put malicious files in arbitrary locations on a victim's computer. This will facilitate a remote compromise.
UPDATE (August 1, 2008): Symantec has observed in-the-wild attacks leveraging a new vector of attack for this issue. The newly discovered vector greatly increases the severity of the flaw because users who do not have the Snapshot Viewer control on their system can be forced to download the control without interaction and can then be exploited.
Snapshot Viewer for Microsoft Access is prone to a vulnerability that can cause malicious files to be downloaded and saved to arbitrary locations on an affected computer.
Attackers may exploit this issue to put malicious files in arbitrary locations on a victim's computer. This will facilitate a remote compromise.
UPDATE (August 1, 2008): Symantec has observed in-the-wild attacks leveraging a new vector of attack for this issue. The newly discovered vector greatly increases the severity of the flaw because users who do not have the Snapshot Viewer control on their system can be forced to download the control without interaction and can then be exploited.
Exploit / POC
Snapshot Viewer for Microsoft Access ActiveX Control Arbitrary File Download Vulnerability
Symantec has detected evidence that this issue is being actively exploited in the wild. Active exploits of this issue are known to be attacking both Chinese and English versions of Microsoft Windows.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
UPDATE: Since an exploit for this issue is now part of a variant of the Neosploit exploit kit, we will likely see widespread exploit attempts of this vulnerability.
UPDATE (August 1, 2008): Symantec has observed in-the-wild attacks leveraging a new vector of attack for this issue. The newly discovered vector greatly increases the severity of the flaw because users who do not have the Snapshot Viewer control on their system can be forced to download the control without interaction and can then be exploited.
The following exploit code is available:
Symantec has detected evidence that this issue is being actively exploited in the wild. Active exploits of this issue are known to be attacking both Chinese and English versions of Microsoft Windows.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
UPDATE: Since an exploit for this issue is now part of a variant of the Neosploit exploit kit, we will likely see widespread exploit attempts of this vulnerability.
UPDATE (August 1, 2008): Symantec has observed in-the-wild attacks leveraging a new vector of attack for this issue. The newly discovered vector greatly increases the severity of the flaw because users who do not have the Snapshot Viewer control on their system can be forced to download the control without interaction and can then be exploited.
The following exploit code is available:
Solution / Fix
Snapshot Viewer for Microsoft Access ActiveX Control Arbitrary File Download Vulnerability
Solution:
The vendor has released a bulletin and updates to address this issue. Please see the referenced advisory for more information.
Microsoft Access 2002 SP3
Microsoft Access 2003
Microsoft Access 2003 SP3
Microsoft Access 2003 SP2
Microsoft Snapshot Viewer for Microsoft Access 0
Microsoft Access 2000 SP3
Solution:
The vendor has released a bulletin and updates to address this issue. Please see the referenced advisory for more information.
Microsoft Access 2002 SP3
-
Microsoft Security Update for Access Snapshot Viewer 2002 (KB955440)
http://www.microsoft.com/downloads/details.aspx?familyid=34b655f8-1922 -4246-94ca-ed381c3e3b13&displaylang=en
Microsoft Access 2003
-
Microsoft Security Update for Access Snapshot Viewer 2003 (KB957198)
http://www.microsoft.com/downloads/details.aspx?FamilyId=7C22BB32-7CE3 -4FF2-8366-BA2EB5135833&displaylang=en
Microsoft Access 2003 SP3
-
Microsoft Security Update for Access Snapshot Viewer 2003 (KB955439)
http://www.microsoft.com/downloads/details.aspx?familyid=fd698517-a504 -427d-9e5f-fde8f102142c&displaylang=en -
Microsoft Security Update for Access Snapshot Viewer 2003 (KB957198)
http://www.microsoft.com/downloads/details.aspx?FamilyId=7C22BB32-7CE3 -4FF2-8366-BA2EB5135833&displaylang=en
Microsoft Access 2003 SP2
-
Microsoft Security Update for Access Snapshot Viewer 2003 (KB955439)
http://www.microsoft.com/downloads/details.aspx?familyid=fd698517-a504 -427d-9e5f-fde8f102142c&displaylang=en -
Microsoft Security Update for Access Snapshot Viewer 2003 (KB957198)
http://www.microsoft.com/downloads/details.aspx?FamilyId=7C22BB32-7CE3 -4FF2-8366-BA2EB5135833&displaylang=en
Microsoft Snapshot Viewer for Microsoft Access 0
-
Microsoft Security Update for Access Snapshot Viewer 2003 (KB957198)
http://www.microsoft.com/downloads/details.aspx?FamilyId=7C22BB32-7CE3 -4FF2-8366-BA2EB5135833&displaylang=en
Microsoft Access 2000 SP3
-
Microsoft Security Update for Access Snapshot Viewer 2000 (KB955441)
http://www.microsoft.com/downloads/details.aspx?familyid=54e4031d-298f -480c-88d5-0ad3b2b62ba9&displaylang=en
References
Snapshot Viewer for Microsoft Access ActiveX Control Arbitrary File Download Vulnerability
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Vulnerability Note VU#837785 (US-CERT)
- Microsoft Security Bulletin MS08-041 �?? Critical (Microsoft)
- Vulnerability in the ActiveX Control for the Snapshot Viewer for Microsoft Acces (Microsoft)