Vulnerability Name:

CVE-2008-1898 (CCN-41876)

Assigned:2008-04-17
Published:2008-04-17
Updated:2018-10-11
Summary:A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and 2007, allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via an invalid WksPictureInterface property value, which triggers an improper function call.
CVSS v3 Severity:10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
8.4 High (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:F/RL:U/RC:UR)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
9.3 High (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
8.4 High (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:F/RL:U/RC:UR)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-20
Vulnerability Consequences:Gain Access
References:Source: CCN
Type: Full-Disclosure Mailing List, Fri May 02 2008 - 04:47:48 CDT
Microsoft Work ActiveX Insecure Method Exploit

Source: FULLDISC
Type: Exploit
20080502 Microsoft Work ActiveX Insecure Method Exploit

Source: CCN
Type: Microsoft Security Response Center Web site
Why there won't be a security update for WkImgSrv.dll

Source: MISC
Type: UNKNOWN
http://blogs.technet.com/swi/archive/2008/06/05/why-there-wont-be-a-security-update-for-wkimgsrv-dll.aspx

Source: MITRE
Type: CNA
CVE-2008-1898

Source: CCN
Type: McAfee Avert Labs Blog, Thursday April 17, 2008 at 11:15 am CST
Potential Microsoft Works ActiveX Zero-Day Surfaces

Source: CCN
Type: Microsoft Works Web site
Microsoft Works Home

Source: CCN
Type: OSVDB ID: 44458
Microsoft Works WkImgSrv.dll WksPictureInterface Property Remote DoS

Source: BUGTRAQ
Type: UNKNOWN
20080417 Microsoft Works 7 WkImgSrv.dll crash POC

Source: BID
Type: Exploit
28820

Source: CCN
Type: BID-28820
Microsoft Works 7 'WkImgSrv.dll' ActiveX Control Remote Code Execution Vulnerability

Source: XF
Type: UNKNOWN
microsoft-works-wkimgsrv-code-execution(41876)

Source: XF
Type: UNKNOWN
microsoft-works-wkimgsrv-dos(41876)

Source: EXPLOIT-DB
Type: UNKNOWN
5460

Source: EXPLOIT-DB
Type: UNKNOWN
5530

Vulnerable Configuration:Configuration 1:
  • cpe:/a:microsoft:office:2003:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:office:2007:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:works:7.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:microsoft:works:7.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    microsoft office 2003
    microsoft office 2007
    microsoft works 7.0
    microsoft works 7.0