Threat Monitor
« Back to list
Troj.Downloader.JS.Agent.edg
| Aliases: | |
|---|
| Pattern: | 200910251638 |
|---|
| Threat Type | Propagation Methods | Systems Affected | Risk Level |
| | | - Windows NT
- Windows XP
- Windows 2000
- Windows 95/98/ME
- MS-DOS
- Other
| |
The Office OCX Word Viewer OCX ActiveX control with the CLSID:97AF4A45-49BE-4485-9F55-91AB40F288F2 is prone to a remote code-execution vulnerability. The vulnerability is caused due to the use of the insecure OpenWebFile() method. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to download arbitrary executable files to the victim's system and execute arbitrary code on the system with the privileges of the victim.
Affected Version: Office OCX Word Viewer OCX 3.2
Back to Top