First published: Wed May 30 2007(Updated: )
Buffer overflow in the HelpPopup method in the Microsoft Office 2000 Controllo UA di Microsoft Office ActiveX control (OUACTRL.OCX) 1.0.1.9 allows remote attackers to cause a denial of service (probably winhlp32.exe crash) via a long first argument. NOTE: it is not clear whether this issue crosses privilege boundaries.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office | =2000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2007-2903 is moderate, due to its potential to cause a denial of service.
To fix CVE-2007-2903, consider upgrading to a later version of Microsoft Office that no longer includes the vulnerable ActiveX control.
CVE-2007-2903 specifically affects Microsoft Office 2000 with the OUACTRL.OCX ActiveX control.
CVE-2007-2903 allows remote attackers to cause a denial of service through a buffer overflow.
Exploiting CVE-2007-2903 can lead to crashes of the winhlp32.exe process on the affected systems.