Microsoft Access ActiveX Control Multiple Instantiation Remote Code Execution Vulnerability
BID:41442
Info
Microsoft Access ActiveX Control Multiple Instantiation Remote Code Execution Vulnerability
| Bugtraq ID: | 41442 |
| Class: | Unknown |
| CVE: |
CVE-2010-0814 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 13 2010 12:00AM |
| Updated: | Jul 26 2010 07:45PM |
| Credit: | An anonymous researcher, working with TippingPoint's Zero Day Initiative |
| Vulnerable: |
Microsoft Access 2007 SP2 Microsoft Access 2007 SP1 Microsoft Access 2007 0 Microsoft Access 2003 SP3 Microsoft Access 2003 SP2 Microsoft Access 2003 |
| Not Vulnerable: | |
Discussion
Microsoft Access ActiveX Control Multiple Instantiation Remote Code Execution Vulnerability
Microsoft Access is prone to a remote code-execution vulnerability that affects ActiveX instantiations.
An attacker can exploit this issue by enticing an unsuspecting user to view a malicious webpage.
Successful exploits will allow the attacker to execute arbitrary code within the context of the application, typically Internet Explorer, that uses the ActiveX control.
Microsoft Access is prone to a remote code-execution vulnerability that affects ActiveX instantiations.
An attacker can exploit this issue by enticing an unsuspecting user to view a malicious webpage.
Successful exploits will allow the attacker to execute arbitrary code within the context of the application, typically Internet Explorer, that uses the ActiveX control.
Exploit / POC
Microsoft Access ActiveX Control Multiple Instantiation Remote Code Execution Vulnerability
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Microsoft Access ActiveX Control Multiple Instantiation Remote Code Execution Vulnerability
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
Microsoft Access 2003 SP3
Microsoft Access 2007 SP2
Microsoft Access 2007 SP1
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
Microsoft Access 2003 SP3
-
Microsoft Security Update for Microsoft Office Access 2003 (KB981716)
http://www.microsoft.com/downloads/details.aspx?familyid=93768ac6-e6d7 -4175-a6e3-666210494678
Microsoft Access 2007 SP2
-
Microsoft Security Update for Microsoft Office Access 2007 (KB979440)
http://www.microsoft.com/downloads/details.aspx?familyid=af2862e2-da37 -4cbe-8974-e517eb666f14
Microsoft Access 2007 SP1
-
Microsoft Security Update for Microsoft Office Access 2007 (KB979440)
http://www.microsoft.com/downloads/details.aspx?familyid=af2862e2-da37 -4cbe-8974-e517eb666f14
References
Microsoft Access ActiveX Control Multiple Instantiation Remote Code Execution Vulnerability
References:
References:
- Microsoft Homepage (Microsoft)
- Microsoft Knowledge Base Article 240797 (Microsoft)
- ZDI-10-117: Microsoft Office Access AccWizObjects ActiveX Control Uninitialized (ZDI Disclosures
) - Microsoft Security Bulletin MS10-044 (Microsoft)
- ZDI-10-117 Microsoft Office Access AccWizObjects ActiveX Control Uninitialized I (Zero Day Initiative)