Arbitrary Code Execution Vulnerability in Microsoft Access Snapshot Viewer

A Microsoft Access vulnerability can result in the execution of arbitrary code on the vulnerable system.

Ken Pfeil

September 2, 2003

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported September 3, 2003, by Microsoft.

 

VERSIONS AFFECTED

 

  • Microsoft Access 2002, 2000, and 97

 

DESCRIPTION

 

A Microsoft Access vulnerability can result in the execution of arbitrary code on the vulnerable system. Because the Snapshot Viewer doesn't correctly validate parameters, a buffer overrun can permit an attacker to execute code of his or her choice under the logged-on user's security context.

 

VENDOR RESPONSE

 

Microsoft has released Security BulletinMS03-038, "Unchecked buffer in Microsoft Access Snapshot Viewer Could Allow Code Execution (827104)," to address this vulnerability and recommends that affected users apply the appropriate patch mentioned in the bulletin.

 

CREDIT

Discovered byOliver Lavery.

Read more about:

Microsoft
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like