If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. |
|
|
Thread Tools | Display Modes |
#1
|
|||
|
|||
US-CERT TA08-189A -- Microsoft Office Snapshot Viewer ActiveX Vulnerability
Concerns MS Office ActiveX vulnerabilities and describes work-around to
issues, -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 National Cyber Alert System Technical Cyber Security Alert TA08-189A Microsoft Office Snapshot Viewer ActiveX Vulnerability Original release date: July 7, 2008 Last revised: -- Source: US-CERT Systems Affected * Microsoft Office Access 2000 * Microsoft Office Access XP * Microsoft Office Access 2003 * Microsoft Office Snapshot Viewer Overview An unpatched vulnerability in the Microsoft Office Snapshot Viewer ActiveX control is being used in attacks. I. Description Microsoft has released Security Advisory (955179) to describe attacks on a vulnerability in the Microsoft Office Snapshot Viewer ActiveX control. Because no fix is currently available for this vulnerability, please see the Security Advisory and US-CERT Vulnerability Note VU#837785 for workarounds. II. Impact A remote, unauthenticated attacker could execute arbitrary code. III. Solution Apply workarounds Microsoft has provided workarounds for this vulnerability in Security Advisory (955179). Additional details and workarounds are provided in US-CERT Vulnerability Note VU#837785. The most effective workaround for this vulnerability is to set kill bits for the Snapshot Viewer ActiveX control, as outlined in the documents noted above. Other workarounds include disabling ActiveX, as specified in the Securing Your Web Browser document, and upgrading to Internet Explorer 7, which can help mitigate the vulnerability with its ActiveX opt-in feature. IV. References * US-CERT Vulnerability Note VU#837785 - http://www.kb.cert.org/vuls/id/837785 * Microsoft Security Advisory (955179) - http://www.microsoft.com/technet/security/advisory/955179.mspx * Securing Your Web Browser - http://www.us-cert.gov/reading_room/securing_browser/ __________________________________________________ __________________ The most recent version of this document can be found at: http://www.us-cert.gov/cas/techalerts/TA08-189A.html __________________________________________________ __________________ Feedback can be directed to US-CERT Technical Staff. Please send email to with "TA08-189A Feedback VU#837785" in the subject. __________________________________________________ __________________ For instructions on subscribing to or unsubscribing from this mailing list, visit http://www.us-cert.gov/cas/signup.html. __________________________________________________ __________________ Produced 2008 by US-CERT, a government organization. Terms of use: http://www.us-cert.gov/legal.html __________________________________________________ __________________ Revision History July 7, 2008: Initial release -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.5 (GNU/Linux) iQEVAwUBSHJ0D3IHljM+H4irAQI4/gf9GMgKMgFwrFpwXqtkcESdNuOqHHBU2z57 tRdKpqpZL0nRY11z5FEx2wBK56/GBYVBn5pGjH9/LpWnbvsqVdt3wePgXHhbAJYW GMhZj4JKa+313sTszdrEUmTZK8gK+QZtx2V3+rSVNhMbnQHVUY xevjUtNGrI5Sni iITq9GVJX7GIQb3aI+uFaxScWD84tf9rnUqP71SmapWvaz5rnT dPH/QPLZtpcoT8 Nw/uQAzekHUfvqbvkUdud39X4IOJKz2Vi10r3QC+gdkHCrNaXtM2R oIfkU9+B3f4 91SBnJpmhwgifILsll9WHHvYATZScUWINUkMMA/vpBXHNxMmXP+7XQ== =lT3a -----END PGP SIGNATURE----- |
Thread Tools | |
Display Modes | |
|
|
Similar Threads | ||||
Thread | Thread Starter | Forum | Replies | Last Post |
U-S Cert Vulnerability Advisories | Dan | General | 0 | July 8th 08 12:21 PM |
US CERT - Security Alert TA08-162C -- Apple Quicktime Updates for Multiple Vulnerabilities | MEB[_2_] | General | 7 | June 19th 08 01:19 AM |
US CERT - Security Alert TA08-162A -- SNMPv3 Authentication Bypass Vulnerability | MEB[_2_] | General | 0 | June 11th 08 07:17 AM |
US CERT - another QuickTime vulnerability warning - other APPLE | MEB[_2_] | General | 2 | April 6th 08 04:41 PM |
Snapshot Viewer | Hazmink | Software & Applications | 1 | June 9th 04 09:29 PM |