6.8
CVSSv2

CVE-2008-2463

Published: 07/07/2008 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 690
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snapshot Viewer and Microsoft Office Access 2000 through 2003, allows remote malicious users to download arbitrary files to a client machine via a crafted HTML document or e-mail message, probably involving use of the SnapshotPath and CompressedPath properties and the PrintSnapshot method. NOTE: this can be leveraged for code execution by writing to a Startup folder.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft office snapshot viewer activex office2000

microsoft office snapshot viewer activex office_2003

microsoft office snapshot viewer activex office_xp

Exploits

/* Microsoft Access Snapshot Viewer ActiveX Control Exploit Ms-Access SnapShot Exploit Snapviewocx v 10055290 Download nice binaries into an arbitrary box Vulnerability discovered by Oliver Lavery wwwsecurityfocuscom/bid/8536/info Remote: Yes greetz to str0ke */ #include <stdioh> #include <stdlibh> # ...
## # $Id: ms08_041_snapshotviewerrb 10394 2010-09-20 08:06:27Z jduck $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/core ...