Symantec.com > Business > Security Response > Attack Signatures > HTTP MS Works 7 WkImgSrv ActiveX Code Execution

HTTP MS Works 7 WkImgSrv ActiveX Code Execution

Severity: High

This attack could pose a serious security threat. You should take immediate action to stop any damage or prevent further damage from happening.

Description

This signature detects attempt to execute remote code by passing specially crafted arguments into a method of Microsoft Works ActiveX Control.

Additional Information

Microsoft Works 7 'WkImgSrv.dll' ActiveX control is prone to a remote code-execution vulnerability because it fails to sufficiently verify user-supplied input.

An attacker can exploit this issue to run arbitrary attacker-supplied code in the context of the currently logged-in user. Failed exploits attempts will trigger denial-of-service conditions.

This issue affects Microsoft Works 7 'WkImgSrv.dll' ActiveX control 7.03.0616; other versions may also be vulnerable.

Affected

  • Microsoft Works 7
  • Microsoft WkImgSrv.dll 7.3.616

Possible False Positives

There are no known false positives associated with this signature.

Additional References