vendor:
Jet 3.51 and 4.0 Driver
by:
yeahright
7.5
CVSS
HIGH
VBA Shell Command Injection
78
CWE
Product Name: Jet 3.51 and 4.0 Driver
Affected Version From: 3.51
Affected Version To: 4
Patch Exists: YES
Related CWE: N/A
CPE: MSJET35.DLL and MSJET40.DLL
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2001
Jet 3.51 and 4.0 Driver Vulnerability
A vulnerability affects Microsoft's Jet 3.51 and 4.0 driver (MSJET35.DLL and MSJET40.DLL). This vulnerability could allow an attacker to create malicious '.xls' or '.doc' files incorporating VBA shell commands. When the file is opened, the shell commands contained in the file will execute on the target system. Command execution will occur in the context of the user that is opening the file.
Mitigation:
Microsoft has released a patch to address this vulnerability.