also @ TechSpot: Windows logo to get a Metro makeover in Windows 8
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Sign up or Login to participate.

Go Back   TechSpot OpenBoards > TechSpot Community > General Discussion

Begin your free trial now Pay-as-you-go options starting at $10/user/month

Flaw in Visual Basic for Applications

Thread Tools Search this Thread
  #1  
Old 09-03-2003
TS | Thomas's Avatar
TechSpot Maniac
 
Location: Ireland
Member since: Feb 2002, 1,327 posts
Flaw in Visual Basic for Applications

Affected Software:
Microsoft Visual Basic for Applications SDK 5.0, 6.0, 6.2 & 6.3
(Please see here for products which include this)

A flaw exists in the way VBA checks document properties passed to it when a document is opened by the host application. A buffer overrun exists which if exploited successfully could allow an attacker to execute code of their choice in the context of the logged on user.

In order for an attack to be successful, a user would have to open a specially crafted document sent to them by an attacker. This document could be any type of document that supports VBA, such as a Word document, Excel spreadsheet, PowerPoint presentation. In the case where Microsoft Word is being used as the HTML e-mail editor for Microsoft Outlook, this document could be an e-mail, however the user would need to reply to, or forward the mail message in order for the vulnerability to be exploited.

Patch availability
Closed Thread

Similar Topics
Topic Replies Forum
C# vs. Visual Basic .Net 4 Software Apps
Visual basic 14 Software Apps
Visual Basic Timer 6 Software Apps
Visual Basic Timer 1 Windows OS

Thread Tools Search this Thread
Search this Thread:

Advanced Search
All times are GMT -4. The time now is 08:54 AM.