Sploitus

Exploit for Microsoft Office Web Components OWC.Spreadsheet.9 HTMLURL property overflow

saint · 2009-08-14

Exploit Code

MARKDOWN31 lines
## https://sploitus.com/exploit?id=SAINT:F2E6998CEAAEFC701657B0FC27101957
Added: 08/14/2009  
CVE: [CVE-2009-1534](<https://vulners.com/cve/CVE-2009-1534>)  
BID: [35992](<http://www.securityfocus.com/bid/35992>)  
OSVDB: [56916](<http://www.osvdb.org/56916>)  


### Background

Microsoft Office Web Components (OWC) are a group of OLE classes implemented as ActiveX controls. 

### Problem

A buffer overflow vulnerability in the `**OWC.Spreadsheet.9**` ActiveX control allows command execution when a user loads a web page which instantiates this control and assigns a long string value to the object's HTMLURL parameter. 

### Resolution

Apply the update referenced in [Microsoft Security Bulletin 09-043](<http://www.microsoft.com/technet/security/bulletin/MS09-043.mspx>). 

### References

<http://www.microsoft.com/technet/security/bulletin/MS09-043.mspx>  


### Limitations

Exploit works on Microsoft Office XP SP3 on Windows XP SP3 English with DEP enabled and requires a user to load the exploit page in Internet Explorer 6 or 7. 

### Platforms

Windows XP