When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

Flaw in Visual Basic for Applications Allows Code Execution

Microsoft VBA is a development technology for developing client desktop packaged applications and integrating them with existing data and systems. Microsoft VBA is based on the Microsoft Visual Basic development system. Microsoft Office products include VBA and make use of VBA to perform certain functions. VBA can also be used to build customized applications based around an existing host application. A flaw exists in the way VBA checks document properties passed to it when a document is opened by the host application. A buffer overrun exists which if exploited successfully could allow an attacker to execute code of their choice in the context of the logged on user. In order for an attack to be successful, a user would have to open a specially crafted document sent to them by an attacker. This document could be any type of document that supports VBA, such as a Word document, Excel spreadsheet or PowerPoint presentation.

Impact: Run code of attackers choice

Max Risk: Critical

Bulletin: MS03-037

View: Microsoft Security Bulletin MS03-037

View: Technet Security Bulletin

Report a problem with article
Next Article

DirectX 9.0 SDK RC0

Previous Article

MSN Beta Program Invitations Sent Out!

Join the conversation!

Login or Sign Up to read and post a comment.

-1 Comments - Add comment