vendor:
Microsoft Forms 2.0 TextBox ActiveX Object
by:
SecurityFocus
7.5
CVSS
HIGH
Microsoft Forms 2.0 TextBox ActiveX Object
20
CWE
Product Name: Microsoft Forms 2.0 TextBox ActiveX Object
Affected Version From: Visual Basic 5.0, Project 98, Outlook 98, or Office 97
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
1998
Microsoft Forms 2.0 TextBox ActiveX Object
A vulnerability exists in Microsoft Forms 2.0 TextBox ActiveX object which allows malicious web forms to access data from the Windows clipboard without the knowledge of the visiting end-user. This control is loaded when Visual Basic 5.0, Project 98, Outlook 98, or Office 97 is installed on the host. An attacker can exploit this vulnerability by using a malicious web form with a TextBox ActiveX object and a function to paste the clipboard data into the text box.
Mitigation:
Microsoft has released a patch to address this vulnerability.