>> Microsoft Products OLE Automation Remote Code Execution (MS08-008)
Title : Microsoft Products OLE Automation Remote Code Execution (MS08-008) VUPEN ID : VUPEN/ADV-2008-0510 CVE ID : CVE-2007-0065
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-02-12
Technical Description
A vulnerability has been identified in Microsoft Windows, Office for Mac and Visual Basic, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected server. This issue is caused by a heap overflow error in Object Linking and Embedding (OLE) Automation when handling specially crafted script requests, which could be exploited by attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.