This application requires Javascript for optimal performance.

MS.Access.Snapshot.Viewer.ActiveX.Control.File.Download

Release Date

Dec 16, 2011

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates a possible attempt to exploit an Arbitrary File Download vulnerability in Microsoft Office Snapshot Viewer ActiveX control.

The vulnerability is located in the "snapview.ocx" ActiveX control through misuse of the "SnapshotPath" and "CompressedPath" properties. It may allow remote attackers to download files to arbitrary locations.

Affected Products

Snapshot Viewer for Microsoft Accesss
Microsoft Office Access 2000
Microsoft Office Access 2002
Microsoft Office Access 2003

Recommended Actions

Refer to the vendor's web site for the suggested workaround.
http://www.microsoft.com/technet/security/advisory/955179.mspx

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2008-2463

Reference: VID-30294