First published: Mon Apr 21 2008(Updated: )
A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and 2007, allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via an invalid WksPictureInterface property value, which triggers an improper function call.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Works Suite | =7.0 | |
Microsoft Office | =2003 | |
Microsoft Office | =2007 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1898 is classified as a critical vulnerability due to its potential to allow remote code execution.
To remediate CVE-2008-1898, users should uninstall or avoid using the affected versions of Microsoft Works or Microsoft Office.
CVE-2008-1898 affects Microsoft Works 7.0, Microsoft Office 2003, and Microsoft Office 2007.
CVE-2008-1898 enables attackers to execute arbitrary code remotely or cause a denial of service, leading to browser crashes.
Anyone using the affected versions of Microsoft Works or Microsoft Office are at risk from CVE-2008-1898.