Multiple Office OCX ActiveX Controls 'OpenWebFile()' Arbitrary Program Execution Vulnerability
BID:33243
Info
Multiple Office OCX ActiveX Controls 'OpenWebFile()' Arbitrary Program Execution Vulnerability
| Bugtraq ID: | 33243 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 13 2009 12:00AM |
| Updated: | Jan 27 2009 10:59PM |
| Credit: | Stack, Cyber-Zone, Houssamix and Mountassif Moad |
| Vulnerable: |
Office OCX Word Viewer OCX 3.2 Office OCX PowerPoint Viewer OCX 3.1 Office OCX Office Viewer OCX 3.0.1 Office OCX Excel Viewer OCX 3.2 |
| Not Vulnerable: | |
Discussion
Multiple Office OCX ActiveX Controls 'OpenWebFile()' Arbitrary Program Execution Vulnerability
Multiple Office OCX ActiveX controls are prone to a vulnerability that lets attackers execute arbitrary remote files.
An attacker can exploit this issue to execute arbitrary code in the context of an application using the affected ActiveX control (typically Internet Explorer). This may aid in further attacks.
The following ActiveX controls are vulnerable:
Office Viewer OCX 3.0.1
Word Viewer OCX 3.2
PowerPoint Viewer OCX 3.1
Excel Viewer OCX 3.2
Multiple Office OCX ActiveX controls are prone to a vulnerability that lets attackers execute arbitrary remote files.
An attacker can exploit this issue to execute arbitrary code in the context of an application using the affected ActiveX control (typically Internet Explorer). This may aid in further attacks.
The following ActiveX controls are vulnerable:
Office Viewer OCX 3.0.1
Word Viewer OCX 3.2
PowerPoint Viewer OCX 3.1
Excel Viewer OCX 3.2
Exploit / POC
Multiple Office OCX ActiveX Controls 'OpenWebFile()' Arbitrary Program Execution Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into viewing a malicious web page.
UPDATE (January 27, 2009): Symantec has detected active exploits of this issue in the wild.
The following example exploits are available:
To exploit this issue, an attacker must entice an unsuspecting victim into viewing a malicious web page.
UPDATE (January 27, 2009): Symantec has detected active exploits of this issue in the wild.
The following example exploits are available:
Solution / Fix
Multiple Office OCX ActiveX Controls 'OpenWebFile()' Arbitrary Program Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Multiple Office OCX ActiveX Controls 'OpenWebFile()' Arbitrary Program Execution Vulnerability
References:
References:
- Excel Viewer OCX Homepage (Office OCX)
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Office Viewer (Office OCX)
- PowerPoint Viewer (Office OCX)
- Word Viewer (Office OCX)