Microsoft Office Web Components OWC.Spreadsheet.9 ActiveX Control overflow
Added: 03/12/2008CVE: CVE-2006-4695
BID: 28135
OSVDB: 42711
Background
Microsoft Office Web Components (OWC) are a group of OLE classes implemented as ActiveX controls.Problem
A buffer overflow vulnerability in the OWC.Spreadsheet.9 ActiveX control allows command execution when a user loads a web page which instantiates this control with a long, specially crafted URL in the CSVData field.Resolution
Apply the update referenced in Microsoft Security Bulletin 08-017.References
http://www.microsoft.com/technet/security/bulletin/MS08-017.mspxLimitations
Exploit works on Microsoft Office 2000 and XP and requires a user to load the exploit page in Internet Explorer.Platforms
WindowsBack to exploit index