A Windows 98 & ME forum. Win98banter

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Go Back   Home » Win98banter forum » Windows 98 » General
Site Map Home Authors List Search Today's Posts Mark Forums Read Web Partners

US-CERT TA08-189A -- Microsoft Office Snapshot Viewer ActiveX Vulnerability



 
 
Thread Tools Display Modes
  #1  
Old July 9th 08, 12:57 AM posted to microsoft.public.win98.gen_discussion
MEB[_2_]
External Usenet User
 
Posts: 1,626
Default US-CERT TA08-189A -- Microsoft Office Snapshot Viewer ActiveX Vulnerability

Concerns MS Office ActiveX vulnerabilities and describes work-around to
issues,


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

National Cyber Alert System

Technical Cyber Security Alert TA08-189A


Microsoft Office Snapshot Viewer ActiveX Vulnerability

Original release date: July 7, 2008
Last revised: --
Source: US-CERT


Systems Affected

* Microsoft Office Access 2000
* Microsoft Office Access XP
* Microsoft Office Access 2003
* Microsoft Office Snapshot Viewer


Overview

An unpatched vulnerability in the Microsoft Office Snapshot Viewer
ActiveX
control is being used in attacks.


I. Description

Microsoft has released Security Advisory (955179) to describe attacks on
a
vulnerability in the Microsoft Office Snapshot Viewer ActiveX control.
Because no fix is currently available for this vulnerability, please see
the
Security Advisory and US-CERT Vulnerability Note VU#837785 for
workarounds.


II. Impact

A remote, unauthenticated attacker could execute arbitrary code.


III. Solution

Apply workarounds

Microsoft has provided workarounds for this vulnerability in Security
Advisory (955179). Additional details and workarounds are provided in
US-CERT Vulnerability Note VU#837785.

The most effective workaround for this vulnerability is to set kill bits
for
the Snapshot Viewer ActiveX control, as outlined in the documents noted
above. Other workarounds include disabling ActiveX, as specified in the
Securing Your Web Browser document, and upgrading to Internet Explorer 7,
which can help mitigate the vulnerability with its ActiveX opt-in
feature.


IV. References

* US-CERT Vulnerability Note VU#837785 -
http://www.kb.cert.org/vuls/id/837785

* Microsoft Security Advisory (955179) -
http://www.microsoft.com/technet/security/advisory/955179.mspx

* Securing Your Web Browser -
http://www.us-cert.gov/reading_room/securing_browser/


__________________________________________________ __________________

The most recent version of this document can be found at:

http://www.us-cert.gov/cas/techalerts/TA08-189A.html
__________________________________________________ __________________

Feedback can be directed to US-CERT Technical Staff. Please send
email to with "TA08-189A Feedback VU#837785" in the
subject.
__________________________________________________ __________________

For instructions on subscribing to or unsubscribing from this
mailing list, visit http://www.us-cert.gov/cas/signup.html.
__________________________________________________ __________________

Produced 2008 by US-CERT, a government organization.

Terms of use:

http://www.us-cert.gov/legal.html
__________________________________________________ __________________


Revision History

July 7, 2008: Initial release




-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)

iQEVAwUBSHJ0D3IHljM+H4irAQI4/gf9GMgKMgFwrFpwXqtkcESdNuOqHHBU2z57
tRdKpqpZL0nRY11z5FEx2wBK56/GBYVBn5pGjH9/LpWnbvsqVdt3wePgXHhbAJYW
GMhZj4JKa+313sTszdrEUmTZK8gK+QZtx2V3+rSVNhMbnQHVUY xevjUtNGrI5Sni
iITq9GVJX7GIQb3aI+uFaxScWD84tf9rnUqP71SmapWvaz5rnT dPH/QPLZtpcoT8
Nw/uQAzekHUfvqbvkUdud39X4IOJKz2Vi10r3QC+gdkHCrNaXtM2R oIfkU9+B3f4
91SBnJpmhwgifILsll9WHHvYATZScUWINUkMMA/vpBXHNxMmXP+7XQ==
=lT3a
-----END PGP SIGNATURE-----


 




Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
U-S Cert Vulnerability Advisories Dan General 0 July 8th 08 12:21 PM
US CERT - Security Alert TA08-162C -- Apple Quicktime Updates for Multiple Vulnerabilities MEB[_2_] General 7 June 19th 08 01:19 AM
US CERT - Security Alert TA08-162A -- SNMPv3 Authentication Bypass Vulnerability MEB[_2_] General 0 June 11th 08 07:17 AM
US CERT - another QuickTime vulnerability warning - other APPLE MEB[_2_] General 2 April 6th 08 04:41 PM
Snapshot Viewer Hazmink Software & Applications 1 June 9th 04 09:29 PM


All times are GMT +1. The time now is 10:43 AM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Copyright ©2004-2024 Win98banter.
The comments are property of their posters.