CVE-2008-2463 describes an arbitrary file download vulnerability in the Microsoft Office Snapshot Viewer ActiveX control (snapview.ocx 10.0.5529.0), affecting standalone Snapshot Viewer and Microsoft Office Access 2000 through 2003. This flaw allows remote attackers to download arbitrary files to a client machine via specially crafted HTML or email, potentially leading to code execution if files are written to a Startup folder. With a CVSS score of 6.8 (medium severity) and an EPSS score indicating high exploitability, this vulnerability can be exploited over the network with medium attack complexity, resulting in partial confidentiality, integrity, and availability impacts. While not on CISA's KEV catalog or currently active on the Hot List, public exploit modules exist in Metasploit and ExploitDB, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
office_2003CPE matchmatch criteria | cpe:2.3:a:microsoft:office_snapshot_viewer_activex:office_2003:*:*:*:*:*:*:* | ||
office_xpCPE matchmatch criteria | cpe:2.3:a:microsoft:office_snapshot_viewer_activex:office_xp:*:*:*:*:*:*:* | ||
office2000CPE matchmatch criteria | cpe:2.3:a:microsoft:office_snapshot_viewer_activex:office2000:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.