Sploitus

CVE-2008-1898

9 known exploits for CVE-2008-1898

A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and 2007, allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via an invalid WksPictureInterface property value, which triggers an improper function call.

Affected products
Office, Works
Microsoft Office
= 2003, 2007
Microsoft Works
= 7.0
Fix
Available
CVSS 2.0
9.3 HIGH
EPSS
52.0% (99th percentile)
Weakness
CWE-20
NVD status
Modified
Published
2008-04-21
CVE-2008-1898 at NVD
Authoritative description, scoring and affected products

9 known exploits for CVE-2008-1898

Proof-of-concept code and exploit modules indexed by Sploitus