Microsoft Works and Office WkImgSrv.dll ActiveX Control Code Execution (CVE-2008-1898)

A vulnerability has been reported in Microsoft Works 7 and Microsoft Office 2003 and 2007. The vulnerability is due to a boundary error while handling an overly large argument. A remote attacker can exploit this issue by enticing a target victim to open a specially crafted web page that would pass the large crafted argument to the vulnerable method.

Leave a Reply