Oval Definition:oval:org.mitre.oval:def:11756
Revision Date:2013-07-29Version:7
Title:ACCWIZ.dll Uninitialized Variable Vulnerability
Description:The FieldList ActiveX control in the Microsoft Access Wizard Controls in ACCWIZ.dll in Microsoft Office Access 2003 SP3 does not properly interact with the memory-access approach used by Internet Explorer and Office during instantiation, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via an HTML document that references this control along with crafted persistent storage data, aka "ACCWIZ.dll Uninitialized Variable Vulnerability."
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2010-1881
Platform(s):Microsoft Windows 2000
Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Vista
Microsoft Windows XP
Product(s):Microsoft Access 2003
Definition Synopsis
  • Access 2003 SP3 or greater is installed
  • AND Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Access\InstallRoot!Path exists
  • AND Accwiz.dll version is less than 11.0.8325.0
  • BACK