Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:5050
HistorySep 04, 2003 - 12:00 a.m.

Microsoft Security Bulletin MS03-038: Unchecked buffer in Microsoft Access Snapshot Viewer Could Allow Code Execution(827104)

2003-09-0400:00:00
vulners.com
17

-----BEGIN PGP SIGNED MESSAGE-----


Title: Unchecked buffer in Microsoft Access Snapshot Viewer
Could Allow Code Execution (827104)
Date: September 3, 2003
Software: Microsoft Access 97
Microsoft Access 2000
Microsoft Access 2002
Impact: Elevation of Privilege
Max Risk: Moderate
Bulletin: MS03-038

Microsoft encourages customers to review the Security Bulletins at:
http://www.microsoft.com/technet/security/bulletin/MS03-038.asp
http://www.microsoft.com/security/security_bulletins/MS03-038.asp


Issue:

With Microsoft Access Snapshot Viewer, you can distribute a snapshot
of a Microsoft Access database that allows the snapshot to be viewed
without having Access installed. For example, a customer may want to
send a supplier an invoice that is generated by using an Access
database. With Microsoft Access Snapshot Viewer, the customer can
package the database so that the supplier can view it and print it
without having Access installed.

The Microsoft Access Snapshot Viewer is available with all versions
of Access - though it is not installed by default - and is also
available as a separate stand-alone. The Snapshot Viewer is
implemented by using an ActiveX control.

A vulnerability exists because of a flaw in the way that Snapshot
Viewer validates parameters. Because the parameters are not correctly
checked, a buffer overrun can occur, which could allow an attacker to
execute the code of their choice in the security context of the
logged-on user.

For an attack to be successful, an attacker would have to persuade a
user to visit a malicious Web site that is under the attacker's
control.

Mitigating Factors:

  •   The Microsoft Access Snapshot Viewer is not installed with 
    

Microsoft Office by default.

  •   An attacker would need to persuade a user to visit a website
    

under the attacker's control for an attack to be successful.

  •   An attacker's code would run with the same permissions as the 
    

user. If a user's permissions were restricted the attacker would
be similarly restricted.

Risk Rating:

-Moderate

Patch Availability:

Acknowledgment:


THE INFORMATION PROVIDED IN THE MICROSOFT KNOWLEDGE BASE IS
PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT DISCLAIMS
ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING THE
WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.
IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE LIABLE
FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT, INCIDENTAL,
CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF
MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE
POSSIBILITY OF SUCH DAMAGES. SOME STATES DO NOT ALLOW THE EXCLUSION
OR LIMITATION OF LIABILITY FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO
THE FOREGOING LIMITATION MAY NOT APPLY.

-----BEGIN PGP SIGNATURE-----
Version: PGP 7.1

iQEVAwUBP1YPOI0ZSRQxA/UrAQF66wgAobaLCfgLn8Xb413ALZmQlkHGquDHDpO1
mbDjDj8clh6rLMtVQ3cSAwwWFJRVEe7rtdta+pd3oKBd694M1+rqWZrtcexlYjrj
WHRjZwA40zDgB1YS/V6UHV1Jc5vdeN2v9jvuIYPGDFrjMgWD0nl7G2SALj1jBn6/
YPjgKzUKn4wZJ2i138ojl/mtIXKWsQJR5eeNqIf2LwjrgH6JVf9Kwyji8TexT2uJ
LJoukN4NIEVlaShLqrwvfrO1lyx0TjOBqRljLe9wedOTU0fPprH6/CBX14lSNW01
st6dfPnEAm+h+FBlArEJV2o98fm1OI2VbHTabT/Iv06yXTqBLrvFKg==
=lHKZ
-----END PGP SIGNATURE-----


You have received this e-mail bulletin because of your subscription to the Microsoft Product
Security Notification Service. For more information on this service, please visit
http://www.microsoft.com/technet/security/notify.asp.

To verify the digital signature on this bulletin, please download our PGP key at
http://www.microsoft.com/technet/security/notify.asp.

To unsubscribe from the Microsoft Security Notification Service, please visit the Microsoft
Profile Center at http://register.microsoft.com/regsys/pic.asp

If you do not wish to use Microsoft Passport, you can unsubscribe from the Microsoft
Security Notification Service via email as described below:
Reply to this message with the word UNSUBSCRIBE in the Subject line.

For security-related information about Microsoft products, please visit the Microsoft
Security Advisor web site at http://www.microsoft.com/security.