vendor:
Excel Viewer OCX
by:
Mountassif Moad a.k.a Stack
9.3
CVSS
HIGH
Remote File execution
94
CWE
Product Name: Excel Viewer OCX
Affected Version From: 3.2
Affected Version To: 3.2
Patch Exists: YES
Related CWE: N/A
CPE: a:microsoft:excel_viewer_ocx
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Excel Viewer OCX 3.2 Remote File execution exploit
This exploit allows a remote attacker to execute arbitrary code on a vulnerable system by using the OpenWebFile method of the Excel Viewer OCX 3.2 ActiveX control. The vulnerability is due to a lack of input validation when handling the OpenWebFile method, which allows an attacker to specify a remote file to be downloaded and executed on the vulnerable system.
Mitigation:
The vendor has released a patch to address this vulnerability.