Remote Code Execution Vulnerability in Microsoft Office Snapshot Viewer
CVE-2008-2463
Currently unrated
What is CVE-2008-2463?
The Microsoft Office Snapshot Viewer contains a vulnerability in the snapview.ocx
ActiveX control, allowing remote attackers to exploit this weakness through specially crafted HTML documents or email messages. By manipulating properties such as SnapshotPath
and CompressedPath
alongside the PrintSnapshot
method, an attacker may download arbitrary files to the client's machine. This capability raises the risk of executing malicious code by leveraging the Startup folder.