20030903 EEYE: VBE Document Property Buffer Overflowmailing list
http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0093.html CVE-2003-0347
Microsoft Visual Basic For Applications SDK 5.0/6.0/6.2/6.3 - Document Handling Buffer Overrun
Record summary
CVE-2003-0347 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.
Description
Heap-based buffer overflow in VBE.DLL and VBE6.DLL of Microsoft Visual Basic for Applications (VBA) SDK 5.0 through 6.3 allows remote attackers to execute arbitrary code via a document with a long ID parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMicrosoft Visual Basic For Applications SDK 5.0/6.0/6.2/6.3 - Document Handling Buffer OverrunExploitDB exploitby eEye Digital Security TeamNot analyzed1 file
References
720030903 EEYE: VBE Document Property Buffer Overflowmailing list
http://marc.info/?l=bugtraq&m=106262077829157&w=2 9666Third-party advisory
http://secunia.com/advisories/9666 VU#804780Third-party advisory
http://www.kb.cert.org/vuls/id/804780 8534vdb entry
http://www.securityfocus.com/bid/8534 MS03-037Vendor advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-037 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2003-0347