First published: Tue Nov 04 2008(Updated: )
Buffer overflow in the DjVu ActiveX Control 3.0 for Microsoft Office (DjVu_ActiveX_MSOffice.dll) allows remote attackers to execute arbitrary code via a long (1) ImageURL property, and possibly the (2) Mode, (3) Page, or (4) Zoom properties.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Djvu ActiveX Control for Microsoft Office | ||
Microsoft Office | =2000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4922 has been classified as a critical vulnerability due to its potential to allow remote code execution.
To fix CVE-2008-4922, ensure that your DjVu ActiveX Control software is updated to the latest version.
CVE-2008-4922 affects systems using DjVu ActiveX Control 3.0 for Microsoft Office, particularly the 2000 version.
CVE-2008-4922 allows attackers to execute arbitrary code on affected systems by exploiting a buffer overflow.
Using Microsoft Office 2000 with the vulnerable DjVu ActiveX Control presents a significant security risk.