cbcvebase.
CVE-2003-0347
published 2003-10-20

CVE-2003-0347: Heap-based buffer overflow in VBE.DLL and VBE6.DLL of Microsoft Visual Basic for Applications (VBA) SDK 5.0 through 6.3 allows remote attackers to execute…

PriorityP352critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
54.87%
98.9th percentile
Heap-based buffer overflow in VBE.DLL and VBE6.DLL of Microsoft Visual Basic for Applications (VBA) SDK 5.0 through 6.3 allows remote attackers to execute arbitrary code via a document with a long ID parameter.

Affected

8 ranges
VendorProductVersion rangeFixed in
microsoftoffice
microsoftoffice
microsoftproject
microsoftproject
microsoftvisio
microsoftvisual_basic
microsoftvisual_basic
microsoftvisual_basic

Detection & IOCsextracted from sources · hover to see the quote

filenameVBE.DLL
filenameVBE6.DLL
bytes
49 44 3D 22 7B 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 41 42 43 44 00 00 00 00
  • Exploit triggers via a malformed .doc file with an oversized ID parameter in the VBA project stream; look for DOC files containing an abnormally long 'ID="{' string (well beyond the standard GUID length of 38 characters) in the embedded VBA project properties.
  • Internet Explorer is an additional attack vector because it may invoke VBA-capable helper applications when handling certain document types; monitor IE spawning Word or other Office processes.
  • The exploit can be triggered via Insert > Object using 'MSPropertyTreeCtl Class' or 'ChoiceBox Class' ActiveX objects embedded in a Word document; presence of these CLSIDs in documents from untrusted sources warrants scrutiny.
  • ·A working commercial exploit exists in CORE IMPACT but is not publicly available or known to be circulating in the wild at time of disclosure.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.