| Microsoft Windows Knowledge Base Article 950749 update not installed (WinMs08kb950749Update) |
|---|
| Vuln ID: | 42095 | |
|---|---|---|
| Risk Level: | Low |
WinMs08kb950749Update |
| Platforms: | Microsoft Jet: 4.0 | |
| Description: | Microsoft Windows Knowledge Base Article 950749 update is not installed on the system, which could allow an attacker to exploit the following vulnerability: Microsoft Jet Engine is vulnerable to a stack-based buffer overflow, caused by improper bounds checking when parsing a MDB file. By persuading a victim to open a specially-crafted MDB file, a remote attacker could cause the victim's application to crash or possibly execute arbitrary code on the victim's system with the privileges of the victim. An attacker could exploit this vulnerability by sending the malicious file as an email attachment or hosting it on a Web site. Microsoft Jet Database Engine (msjet40.dll) is vulnerable to a stack-based buffer overflow, caused by improper bounds checking when parsing a Word file. By persuading a victim to open a specially-crafted Word file, a remote attacker could cause the victim's application to crash or possibly execute arbitrary code on the victim's system with the privileges of the victim. An attacker could exploit this vulnerability by sending the malicious file as an email attachment or by hosting it on a Web site. |
|
| Remedy: | Apply the appropriate patch for your system, as listed in Microsoft Security Bulletin MS08-028. See References. |
|
| False Positives: | ||
| False Negatives: | ||
| Required Permission: | Windows login | |
| Additional Information: | ||
| References: | Microsoft Security Bulletin MS08-028 IBM Internet Security Systems X-Force Database IBM Internet Security Systems X-Force Database ISS X-Force CVE CVE-2008-1092 |
|
![]() Know Your Risks |
![]() Common Vulnerabilties & Exposures |