CVE-2003-0347
published 2003-10-20CVE-2003-0347: Heap-based buffer overflow in VBE.DLL and VBE6.DLL of Microsoft Visual Basic for Applications (VBA) SDK 5.0 through 6.3 allows remote attackers to execute…
PriorityP352critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
54.87%
98.9th percentile
Heap-based buffer overflow in VBE.DLL and VBE6.DLL of Microsoft Visual Basic for Applications (VBA) SDK 5.0 through 6.3 allows remote attackers to execute arbitrary code via a document with a long ID parameter.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | project | — | — |
| microsoft | project | — | — |
| microsoft | visio | — | — |
| microsoft | visual_basic | — | — |
| microsoft | visual_basic | — | — |
| microsoft | visual_basic | — | — |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
49 44 3D 22 7B 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 41 42 43 44 00 00 00 00
- →Exploit triggers via a malformed .doc file with an oversized ID parameter in the VBA project stream; look for DOC files containing an abnormally long 'ID="{' string (well beyond the standard GUID length of 38 characters) in the embedded VBA project properties. ↗
- →Internet Explorer is an additional attack vector because it may invoke VBA-capable helper applications when handling certain document types; monitor IE spawning Word or other Office processes. ↗
- →The exploit can be triggered via Insert > Object using 'MSPropertyTreeCtl Class' or 'ChoiceBox Class' ActiveX objects embedded in a Word document; presence of these CLSIDs in documents from untrusted sources warrants scrutiny. ↗
- ·A working commercial exploit exists in CORE IMPACT but is not publicly available or known to be circulating in the wild at time of disclosure. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0093.htmlhttp://marc.info/?l=bugtraq&m=106262077829157&w=2http://secunia.com/advisories/9666http://www.kb.cert.org/vuls/id/804780http://www.securityfocus.com/bid/8534https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-037http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0093.htmlhttp://marc.info/?l=bugtraq&m=106262077829157&w=2http://secunia.com/advisories/9666http://www.kb.cert.org/vuls/id/804780http://www.securityfocus.com/bid/8534https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-037
2003-10-20
Published