Secunia Advisory SA40554Microsoft Office Access ActiveX Controls Two Vulnerabilities
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
Two vulnerabilities have been reported in Microsoft Office, which can be exploited by malicious people to compromise a user's system. 1) An error in the ImexGrid and FieldList ActiveX controls (ACCWIZ.dll) when instantiated in a particular order can be exploited to transfer control into unallocated memory. 2) Use of an uninitialised variable in the FieldList ActiveX control can be exploited to corrupt memory via specially crafted persisted storage data. Solution Provided and/or discovered by Alternate/detailed remediation Deep Links Do you have additional information related to this advisory?Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this information to vuln@secunia.com
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||