|
Issues the date: 2008-07-07
Renewal date: 2008-07-08
Is affected the system:
Microsoft Access 2003
Microsoft Access 2002
Microsoft Access 2000
Description:
--------------------------------------------------------------------------------
BUGTRAQ ID: 30114
CVE(CAN) ID: CVE-2008-2463
Microsoft Access is in the Microsoft Office suite relational database management system.
In Microsoft Access tied up snapshot examination ActiveX to control the examination Access report form snapshot which used in facilitating, should control not correct confirmation certain input parameter. If the user were deceived visited malicious stand, possibly caused the stand in the document to download to the user machine's optional position. At present this crack by positive use.
<* origin: Bill Sisk
Link: http://secunia.com/advisories/30883/
http://www.kb.cert.org/vuls/id/837785
http://www.microsoft.com/technet/security/advisory/955179.mspx?pf=true
http://blogs.technet.com/msrc/archive/2008/07/07/snapshot-viewer-activex-control-vulnerability.aspx
http://www.us-cert.gov/cas/techalerts/TA08-189A.html
*>
Suggested:
--------------------------------------------------------------------------------
Temporary solution:
* establishes kill bit as below CLSID:
{F0E42D50-368C-11D0-AD81-00A0C90DC8D9}
{F0E42D60-368C-11D0-AD81-00A0C90DC8D9}
{F2175210-368C-11D0-AD81-00A0C90DC8D9}
Or below the text preservation will be the .REG document and inducts:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Internet Explorer \ ActiveX Compatibility \ {F0E42D50-368C-11D0-AD81-00A0C90DC8D9}]
“Compatibility Flags " =dword:00000400
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Internet Explorer \ ActiveX Compatibility \ {F0E42D60-368C-11D0-AD81-00A0C90DC8D9}]
“Compatibility Flags " =dword:00000400
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Internet Explorer \ ActiveX Compatibility \ {F2175210-368C-11D0-AD81-00A0C90DC8D9}]
“Compatibility Flags " =dword:00000400
Manufacturer patch:
Microsoft
---------
At present the manufacturer has not provided the patch or the promotion procedure, we suggested that uses this software's user momentarily to pay attention to the manufacturer the main page to gain the newest edition:
http://www.microsoft.com/technet/security/
|