CVE-2008-1898: Input Validation
A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and 2007, allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via an invalid WksPictureInterface property value, which triggers an improper function call.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1898?
CVE-2008-1898 is classified as a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2008-1898?
To remediate CVE-2008-1898, users should uninstall or avoid using the affected versions of Microsoft Works or Microsoft Office.
What versions of Microsoft software are affected by CVE-2008-1898?
CVE-2008-1898 affects Microsoft Works 7.0, Microsoft Office 2003, and Microsoft Office 2007.
What type of attack does CVE-2008-1898 enable?
CVE-2008-1898 enables attackers to execute arbitrary code remotely or cause a denial of service, leading to browser crashes.
Who is impacted by CVE-2008-1898?
Anyone using the affected versions of Microsoft Works or Microsoft Office are at risk from CVE-2008-1898.