peter bassill · operator
$ cve CVE-2008-2463 JSON

CVE-2008-2463 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 59.1% (pctl 99)

Patch early

A public exploit exists.

Description

The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snapshot Viewer and Microsoft Office Access 2000 through 2003, allows remote attackers to download arbitrary files to a client machine via a crafted HTML document or e-mail message, probably involving use of the SnapshotPath and CompressedPath properties and the PrintSnapshot method. NOTE: this can be leveraged for code execution by writing to a Startup folder.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS59.13% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2008-07-07
Last modified2026-06-16

Affected (1)

VendorProduct
microsoftoffice snapshot viewer activex

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD