>> Microsoft Office OneNote URL Code Execution (MS08-055)
Title : Microsoft Office OneNote URL Code Execution (MS08-055) VUPEN ID : VUPEN/ADV-2008-2523 CVE ID : CVE-2008-3007 CWE ID : CWE-20
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-09-09
Technical Description
A vulnerability has been identified in Microsoft Office, which could be exploited by remote attackers to take complete control of an input validation error when a specially crafted uniform resource locator is passed to open a specially crafted OneNote file, which could be exploited by attackers to crash an affected application or execute arbitrary code by tricking a user into clicking on specially crafted URL using the OneNote protocol handler (onenote://).