CVE-2008-1898
A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and 2007, allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via an invalid WksPictureInterface property value, which triggers an improper function call.
- Microsoft Office
- = 2003, 2007
- Microsoft Works
- = 7.0
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- EPSS
- 52.0% (99th percentile)
- Weakness
- CWE-20
- NVD status
- Modified
- Published
- 2008-04-21
CVE-2008-1898 at NVD
9 known exploits for CVE-2008-1898
Proof-of-concept code and exploit modules indexed by Sploitus
Microsoft Works 7 - 'WkImgSrv.dll' WKsPictureInterface() ActiveX (Metasploit)
Microsoft Works 7 WkImgSrv.dll WKsPictureInterface() ActiveX Exploit
Microsoft Works WkImgSrv.dll ActiveX Control WksPictureInterface vulnerability
Microsoft Works WkImgSrv.dll ActiveX Control WksPictureInterface vulnerability
Microsoft Works WkImgSrv.dll ActiveX Control WksPictureInterface vulnerability
Microsoft Works WkImgSrv.dll ActiveX Control WksPictureInterface vulnerability
Microsoft Works 7 - 'WkImgSrv.dll' ActiveX Remote Buffer Overflow
DSquare Exploit Pack: D2SEC_WORKS7
Microsoft Works 7 - 'WkImgSrv.dll' ActiveX Denial of Service (PoC)