CVE-2008-1898
HIGH 9.3EPSS 52.0%
A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and 2007, allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via an invalid WksPictureInterface property value, which triggers an improper function call.
- CVSS v2.0
- 9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C - EPSS
- 52.03% chance of exploitation in the next 30 days, 99th percentile
- Published
- 2008-04-21
- Updated
- 2024-08-07
Proof-of-concept exploits (2)
- http://archives.neohapsis.com/archives/fulldisclosure/2008-05/0029.html
- http://www.securityfocus.com/archive/1/491027/100/0/threaded
Metasploit modules (1)
ExploitDB entries (3)
- https://www.exploit-db.com/exploits/16649
- https://www.exploit-db.com/exploits/5530
- https://www.exploit-db.com/exploits/5460