Lucene search

K
nvd[email protected]NVD:CVE-2008-2463
HistoryJul 07, 2008 - 11:41 p.m.

CVE-2008-2463

2008-07-0723:41:00
CWE-94
web.nvd.nist.gov
4

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.8

Confidence

Low

EPSS

0.97

Percentile

99.8%

The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snapshot Viewer and Microsoft Office Access 2000 through 2003, allows remote attackers to download arbitrary files to a client machine via a crafted HTML document or e-mail message, probably involving use of the SnapshotPath and CompressedPath properties and the PrintSnapshot method. NOTE: this can be leveraged for code execution by writing to a Startup folder.

Affected configurations

Nvd
Node
microsoftoffice_snapshot_viewer_activexMatchoffice_2003
OR
microsoftoffice_snapshot_viewer_activexMatchoffice_xp
OR
microsoftoffice_snapshot_viewer_activexMatchoffice2000
VendorProductVersionCPE
microsoftoffice_snapshot_viewer_activexoffice_2003cpe:2.3:a:microsoft:office_snapshot_viewer_activex:office_2003:*:*:*:*:*:*:*
microsoftoffice_snapshot_viewer_activexoffice_xpcpe:2.3:a:microsoft:office_snapshot_viewer_activex:office_xp:*:*:*:*:*:*:*
microsoftoffice_snapshot_viewer_activexoffice2000cpe:2.3:a:microsoft:office_snapshot_viewer_activex:office2000:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.8

Confidence

Low

EPSS

0.97

Percentile

99.8%