vendor:
Microsoft Office 2000
by:
shinnai
7.5
CVSS
HIGH
Remote Buffer Overflow and Denial of Service
CWE
Product Name: Microsoft Office 2000
Affected Version From: Microsoft Office 2000 Controllo UA di Microsoft Office (OUACTRL.OCX v. 1.0.1.9)
Affected Version To: Microsoft Office 2000 Controllo UA di Microsoft Office (OUACTRL.OCX v. 1.0.1.9)
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows
2007
Microsoft Office 2000 Controllo UA di Microsoft Office (OUACTRL.OCX v. 1.0.1.9) “HelpPopup” method Remote Buffer Overflow and winhlp32.exe Denial of Service
The exploit involves a remote buffer overflow and denial of service vulnerability in Microsoft Office 2000 Controllo UA di Microsoft Office (OUACTRL.OCX v. 1.0.1.9) "HelpPopup" method. By clicking a button on a webpage, an attacker can trigger the vulnerability and execute arbitrary code remotely or cause a denial of service condition in the winhlp32.exe process.
Mitigation:
Upgrade to a patched version of Microsoft Office or apply the necessary security patches. Disable ActiveX controls in web browsers.