Microsoft Access 'AccWizObjects' ActiveX Control Remote Code Execution Vulnerability
BID:41444
Info
Microsoft Access 'AccWizObjects' ActiveX Control Remote Code Execution Vulnerability
| Bugtraq ID: | 41444 |
| Class: | Unknown |
| CVE: |
CVE-2010-1881 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 13 2010 12:00AM |
| Updated: | Jul 26 2010 07:45PM |
| Credit: | Robert Freeman of IBM ISS X-Force |
| Vulnerable: |
Microsoft Access 2003 SP3 Microsoft Access 2003 SP2 Microsoft Access 2003 |
| Not Vulnerable: | |
Discussion
Microsoft Access 'AccWizObjects' ActiveX Control Remote Code Execution Vulnerability
Microsoft Access is prone to a remote code-execution vulnerability that affects the 'AccWizObjects' ActiveX control.
An attacker can exploit this issue by enticing an unsuspecting user to view a malicious webpage.
Successful exploits will allow the attacker to execute arbitrary code within the context of the application, typically Internet Explorer, that uses the ActiveX control.
Microsoft Access is prone to a remote code-execution vulnerability that affects the 'AccWizObjects' ActiveX control.
An attacker can exploit this issue by enticing an unsuspecting user to view a malicious webpage.
Successful exploits will allow the attacker to execute arbitrary code within the context of the application, typically Internet Explorer, that uses the ActiveX control.
Exploit / POC
Microsoft Access 'AccWizObjects' ActiveX Control Remote Code Execution Vulnerability
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Microsoft Access 'AccWizObjects' ActiveX Control Remote Code Execution Vulnerability
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
Microsoft Access 2003 SP3
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
Microsoft Access 2003 SP3
-
Microsoft Security Update for Microsoft Office Access 2003 (KB981716)
http://www.microsoft.com/downloads/details.aspx?familyid=93768ac6-e6d7 -4175-a6e3-666210494678
References
Microsoft Access 'AccWizObjects' ActiveX Control Remote Code Execution Vulnerability
References:
References:
- Microsoft Homepage (Microsoft)
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Microsoft Security Bulletin MS10-044 (Microsoft)