Vulnerabilities > CVE-2007-2496 - Multiple vulnerability in Office OCX Word Viewer OCX 3.2.0.5

047910
CVSS 7.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
COMPLETE
network
low complexity
office-ocx
exploit available

Summary

The WordOCX ActiveX control in WordViewer.ocx 3.2.0.5 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1) DoOleCommand, (2) FTPDownloadFile, (3) FTPUploadFile, (4) HttpUploadFile, (5) GotoPage, (6) Save, (7) SaveWebFile, (8) HttpDownloadFile, (9) Open, (10) OpenWebFile, (11) SaveAs, or (12) ShowWordStandardDialog property value.

Vulnerable Configurations

Part Description Count
Application
Office_Ocx
1

Exploit-Db

descriptionWord Viewer OCX 3.2 Remote Denial of Service Exploit. CVE-2007-2496. Dos exploit for windows platform
idEDB-ID:3836
last seen2016-01-31
modified2007-05-03
published2007-05-03
reportershinnai
sourcehttps://www.exploit-db.com/download/3836/
titleWord Viewer OCX 3.2 - Remote Denial of Service Exploit