Skip to content

customize
National Cyber Alert System
Technical Cyber Security Alert TA08-189A archive

Microsoft Office Snapshot Viewer ActiveX Vulnerability

Original release date: July 7, 2008
Last revised: --
Source: US-CERT

Systems Affected

  • Microsoft Office Access 2000
  • Microsoft Office Access XP
  • Microsoft Office Access 2003
  • Microsoft Office Snapshot Viewer

Overview

An unpatched vulnerability in the Microsoft Office Snapshot Viewer ActiveX control is being used in attacks.


I. Description

Microsoft has released Security Advisory (955179) to describe attacks on a vulnerability in the Microsoft Office Snapshot Viewer ActiveX control. Because no fix is currently available for this vulnerability, please see the Security Advisory and US-CERT Vulnerability Note VU#837785 for workarounds.


II. Impact

A remote, unauthenticated attacker could execute arbitrary code.


III. Solution

Apply workarounds

Microsoft has provided workarounds for this vulnerability in Security Advisory (955179). Additional details and workarounds are provided in US-CERT Vulnerability Note VU#837785.

The most effective workaround for this vulnerability is to set kill bits for the Snapshot Viewer ActiveX control, as outlined in the documents noted above. Other workarounds include disabling ActiveX, as specified in the Securing Your Web Browser document, and upgrading to Internet Explorer 7, which can help mitigate the vulnerability with its ActiveX opt-in feature.


IV. References


Feedback can be directed to US-CERT.


Produced 2008 by US-CERT, a government organization. Terms of use

Revision History

July 7, 2008: Initial release

Last updated July 07, 2008
print this document