← Back

CVE-2010-0814

nvd nist
Published: Jul 15, 2010Modified: Apr 29, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

The Microsoft Access Wizard Controls in ACCWIZ.dll in Microsoft Office Access 2003 SP3 and 2007 SP1 and SP2 do not properly interact with the memory-allocation approach used by Internet Explorer during instantiation, which allows remote attackers to execute arbitrary code via a web site that references multiple ActiveX controls, as demonstrated by the ImexGrid and FieldList controls, aka "Access ActiveX Control Vulnerability."

Affected (3)

Products: Microsoft: Access
1 product
Access
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 2003 sp3
Running on/withPlatform Versions
Microsoft
Office
Version 2003 sp3
Configuration B
2 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Microsoft
Version 2007 sp1
Version 2007 sp2
Running on/withPlatform Versions
Microsoft
Office
Version 2007 sp1
Microsoft
Office
Version 2007 sp2

Timeline

No history available yet.