Internet Explorer - Snapshot Viewer for Microsoft Access Arbitrary File Download Variant 2

Strike ID:
E08-1wf04
CVSS:
6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P)
False Positive:
f
Variants:
1
Year:
2008

Description

This strike exploits a malicious instantiation of the Snapshot Viewer for Microsoft Access ActiveX control. Due to a design error, a malicious web page may silently download executable files from an Internet site to any location on the victim's hard drive, including auto-start extensibility points (ASEPs). These programs, in turn, may then silently run with the privileges of the currently-logged on user.

CVE

Bid