56916 : Microsoft Office Web Components HTMLURL Parameter ActiveX Spreadsheet Object Handling Overflow
Printer | http://osvdb.org/56916 | Email This | Edit Vulnerability

Views This Week Views All Time Added to OSVDB Last Modified Modified (since 2008) Percent Complete
18 2822 over 2 years ago about 1 year ago 16 times 80%

Timeline

Vendor Informed Date Vendor Ack Date Disclosure Date Vendor Solution Date
2008-03-17 2008-03-17 2009-08-11 2009-08-11
Time to Patch
512 days

Keywords

CLSID:0002E512-0000-0000-C000-000000000046

Description

Office Web Components is prone to an overflow condition. The ActiveX control fails to properly sanitize user-supplied input via the HTMLURL parameter resulting in a buffer overflow. With a specially crafted website, a context-dependent attacker can potentially cause arbitrary code execution.

Classification

Location: Remote / Network Access, Local / Remote, Context Dependent
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Patch / RCS
Exploit: Exploit Public, Exploit Private, Exploit Commercial
Disclosure: Vendor Verified, Coordinated Disclosure
OSVDB: Web Related

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, Microsoft has released a patch to address this vulnerability.

Products

Unknown or Incomplete

References

Tools & Filters

Snort

15858 15859
40562

Credit

CVSSv2 Score

CVSSv2 Base Score = 9.3
Source: nvd.nist.gov | Generated: 2009-08-12 | Disagree?

Access_vector_2 Access_complexity_1 Authentication_2 Confidentiality_impact_2 Integrity_impact_2 Availability_impact_2

Blogs

This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.

2009/08/22 10:56:16 | Weekly Summary of the "DHS Daily Open Source Infrastructure Report"

from: (ISC)2 Blog

The DHS Daily Open Source Infrastructure Report covers the publicly reported material for the preceding day(s) not previously covered.  This weekly summary provides a selection of those items of greatest significance to the InfoSec professional.   Week Ending:  Friday, August 21, 2009 Infrastructure Report for 17 August 2009 A bug fix takes two years to release!   Should this be where you place your trust? 48.

2009/08/27 06:22:38 | Mass Injection of Chinese College Web Sites

from: Lab Technology

Recently, since Microsoft released information about new vulnerabilities in MS Office and DirectShow in July, attacks spreading through the infection of thousands of legitimate Web sites have increased sharply in the wild. Coinciding with the student recruitment period after the Chinese National College Entrance Examination, the Web sites of universities and some higher education institutions have become the major targets of attackers.

2009/08/15 21:30:33 | The Microsoft OWC two-year vulnerability patch

from: IT Security

For two years, Microsoft put off patching a critical vulnerability. That all changed in July. ————————————————————————————— In March 2007, Peter Vreugdenhil discovered an arbitrary code execution vulnerability in Microsoft’s Office Web Components. As the Zero Day Initiative (ZDI) reported to Microsoft at the time, an exploit involving maliciously crafted parameters when calling msDataSourceObject() could induce memory management errors that could be used to execute malicious code.

2009/08/13 00:00:00 | MS09-043: Description of the security update for Microsoft Office 2000 Web Components 2000 for Microsoft BizTalk Server 2002

from: DotNetSlackers Latest ASP.NET News

971388 ... MS09-043: Description of the security update for Microsoft Office 2000 Web Components 2000 for Microsoft BizTalk Server 2002This RSS feed provided by kbAlerz.com.Visit kbAlertz.com to subscribe. It's 100% free and you'll be able to recieve e-mail or RSS updates for the technologies you pick from the Microsoft Knowledge Base.... Did you know that DotNetSlackers also publishes .net articles written by top known .net Authors? We already have over 80 articles in several categories including Silverlight.

2009/08/12 07:22:12 | MS09-043: Description of the security update for Office 2003 Web Components and Office XP Web Components in Office 2003: August 11, 2009

from: Microsoft Patch Watch

MS09-043: Description of the security update for Office 2003 Web Components and Office XP Web Components in Office 2003: August 11, 2009 No tags for this post. Related postsNo related posts.

2009/08/25 17:35:00 | The Fragus Exploit Kit

from: Web Security Blog by Purewire

Recently, Purewire's Malicious Javascript Detection (MJD) engine identified malicious URLs backed by what was found to be Fragus, a new exploit kit that appeared in late July 2009. An example of a Fragus URL and a screenshot of its admin control panel login page are shown directly below. hxxp://blt.kz/1/show.php?s=5015ba5606 Fragus Admin Control Panel Login As with most modern exploit kits, Fragus serves not one, but a grab bag of exploits that attack the browser, ActiveX controls, and third party plugins.

2009/08/25 16:57:28 | August 2009 Threatscape: ZBot detected in record levels, fresh vulnerabilities consistently attacked

from: Fortinet FortiGuard Blog

Total detected malware volume continued a climbing trend this period , posting the highest levels detected to date this year. On top of this steep incline, highlighted since March 2009, the amount of distinct variants (malicious pieces of code) has also continued to gradually increase. Several malware attack waves were evident this period, most notably on the 24th of July when a huge surge of ZBot activity occurred through HTML/Agent.E!tr .

2009/08/22 14:35:02 | Internet Security Alliance Review 8-22-09

from: Information Security Resources

From The Internet Security Alliance In The News… August 21, US-CERT – Current Activity - Adobe Releases Security Bulletin for Flex SDK . Adobe has released security bulletin APSB09-13 to address a vulnerability in Flex 3.3 SDK and earlier versions. This vulnerability may allow an attacker to conduct a cross-site scripting attack. US-CERT encourages users and administrators to review Adobe security bulletin APSB09-13 and update to Flex 3.4 SDK to help mitigate the risks.

Comments

No Comments.

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2012 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use