CVE-2007-2903: Buffer Overflow
Buffer overflow in the HelpPopup method in the Microsoft Office 2000 Controllo UA di Microsoft Office ActiveX control (OUACTRL.OCX) 1.0.1.9 allows remote attackers to cause a denial of service (probably winhlp32.exe crash) via a long first argument. NOTE: it is not clear whether this issue crosses privilege boundaries.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2903?
The severity of CVE-2007-2903 is moderate, due to its potential to cause a denial of service.
How do I fix CVE-2007-2903?
To fix CVE-2007-2903, consider upgrading to a later version of Microsoft Office that no longer includes the vulnerable ActiveX control.
What software is affected by CVE-2007-2903?
CVE-2007-2903 specifically affects Microsoft Office 2000 with the OUACTRL.OCX ActiveX control.
What type of attack does CVE-2007-2903 facilitate?
CVE-2007-2903 allows remote attackers to cause a denial of service through a buffer overflow.
What is the impact of exploiting CVE-2007-2903?
Exploiting CVE-2007-2903 can lead to crashes of the winhlp32.exe process on the affected systems.