Update Protection against Microsoft Access Snapshot Viewer ActiveX Control Remote Code Execution Vulnerability (MS08-041)
| Check Point Reference: | CPAI-2008-096 | |
| Date Published: | ||
| Severity: | ||
| Last Updated: | ||
| Source: | Microsoft Security Advisory (955179) Microsoft Security Bulletin MS08-041 |
|
| Industry Reference(s): | CVE-2008-2463 US-CERT VU#837785 |
|
| Protection Provided by: |
VPN-1
|
|
| Who is Vulnerable? Microsoft Office Access 2000 Microsoft Office Access 2002 Microsoft Office Access 2003 | ||
| Vulnerability Description A remote code execution vulnerability has been discovered in the Snapshot Viewer for Microsoft Access. Microsoft Snapshot Viewer is an application that allows viewing of snapshots created with any version of Microsoft Access. A remote attacker can exploit this vulnerability to execute arbitrary code on a vulnerable system. |
||
|
Update/Patch Available Apply patches: Microsoft Security Bulletin MS08-041 |
|
|
Vulnerability Details The vulnerability is due to an error in the Snapshot Viewer ActiveX control. To trigger this issue, an attacker may create a malicious web page that will enable him to download arbitrary files to a client machine. Successful exploitation may allow execution of arbitrary code on the vulnerable system. |
Protection Overview
By enabling this protection, SmartDefense will detect and block the vulnerable ActiveX Control. Depending on the traffic mix, activating this protection may result in performance degradation.
In order for the protection to be activated, update your VPN-1/InterSpect product to the latest SmartDefense update. For information on how to update SmartDefense, go to SBP-2006-05, Protection tab and select the version of your choice.
To configure the defense, select your product from the list below and follow the related protection steps.