CVE-2003-0347: Buffer Overflow
Published Sep 4, 2003
·Updated
Heap-based buffer overflow in VBE.DLL and VBE6.DLL of Microsoft Visual Basic for Applications (VBA) SDK 5.0 through 6.3 allows remote attackers to execute arbitrary code via a document with a long ID parameter.
Affected Software
13 affected components
Microsoft Visual Basic=6.3
Microsoft Visual Basic=5.0
Microsoft Project=2000
Microsoft Office=2000
Microsoft Visio=2002
Microsoft Project=2002
Microsoft Office=xp-sp2
Microsoft Visual Basic=6.2
Microsoft Office=2000-sp2
Microsoft Office=2000-sp3
Microsoft Office=xp
Microsoft Visual Basic=6.2
Microsoft Office=xp-sp1
Remediation
Patch Available
Event History
Sep 4, 2003
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Oct 20, 2003
Data Sourced
via NVD·04:00 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0347?
CVE-2003-0347 has a severity rating of high due to its potential to allow remote code execution.
2
How do I fix CVE-2003-0347?
To fix CVE-2003-0347, apply the latest patches or updates provided by Microsoft for the affected software.
3
What software is affected by CVE-2003-0347?
CVE-2003-0347 affects Microsoft Office 2000, Office XP, and certain versions of Visual Basic for Applications SDK.
4
What type of vulnerability is CVE-2003-0347?
CVE-2003-0347 is classified as a heap-based buffer overflow vulnerability.
5
Can CVE-2003-0347 be exploited remotely?
Yes, CVE-2003-0347 can be exploited remotely via a specially crafted document containing a long ID parameter.