Office.OCX.ActiveX.Control.OpenWebFile

NameOffice.OCX.ActiveX.Control.OpenWebFile.Program.Execution
Alias/esMS.Office.ActiveX.Control.OpenWebFile.Program.Execution
Last Updated DateSep 24, 2009
Release DateMar 24, 2009
SeverityMedium
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
DescriptionThis indicates an attack attempt against an arbitrary program download and execution vulnerability in multiple Office OCX ActiveX controls.

The vulnerability is caused by an error when the vulnerable software handles a specially crafted web page.
Affected ProductsOffice OCX Word Viewer OCX 3.2
Office OCX PowerPoint Viewer OCX 3.1
Office OCX Office Viewer OCX 3.0.1
Office OCX Excel Viewer OCX 3.2
Recommended ActionsCurrently we are not aware of any vendor supplied patch for this issue.
Reference/shttp://www.securityfocus.com/bid/33243 (BugTraq)
Reference: VID-17303