Public exploits available
On this page
A remote code execution vulnerability exists in the ActiveX control for the Snapshot Viewer for Microsoft Access. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution.
An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user.
Technical details (analysis)
This vulnerability is caused by a synchronization issue when saving files using the ActiveX control for Snapshot Viewer.
Microsoft Office 2000 Service Pack 3
Microsoft Office XP Service Pack 3
Microsoft Office 2003 Service Pack 2
Microsoft Office 2003 Service Pack 3
All applications not on the affected list.
Release Date: 2008-10-15T00:00:00
Known false positives
This signature can cause false positives if you are not running any of the affected software versions or if you've already applied the patch
Prevent COM objects from running in Internet Explorer
Configure Internet Explorer to prompt before running Active Scripting or to disable Active Scripting in the Internet and Local intranet security zone
Set Internet and Local intranet security zone settings to High to prompt before running ActiveX Controls and Active Scripting in these zones