Vulnerability record · CVE-2008-1898 · published 21 April 2008
CVE-2008-1898: Microsoft Works and Office ActiveX control in WkImgSrv.dll allows remote code execution
Microsoft · Office
An ActiveX control in WkImgSrv.dll 7.03.0616.0, shipped with Microsoft Works 7 and Office 2003/2007, mishandles an invalid WksPictureInterface property value, causing an improper function call. A remote attacker can trigger this through a crafted web page, leading to arbitrary code execution or a browser crash. The flaw is an input validation failure in a widely deployed component.
Description
A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and 2007, allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via an invalid WksPictureInterface property value, which triggers an improper function call.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityCVSS 9.3 and public exploit code with high EPSS indicate a severe, remotely exploitable flaw, though no vendor patch is available and exploitation requires user interaction.
What it is
An ActiveX control in WkImgSrv.dll 7.03.0616.0, shipped with Microsoft Works 7 and Office 2003/2007, mishandles an invalid WksPictureInterface property value, causing an improper function call. A remote attacker can trigger this through a crafted web page, leading to arbitrary code execution or a browser crash. The flaw is an input validation failure in a widely deployed component.
Impact
An attacker can execute arbitrary code in the context of the victim's browser or crash it, giving full control of the affected process. Successful exploitation can lead to system compromise under the user's privileges.
Attack surface
Reached remotely over the network via a malicious web page that instantiates the ActiveX control; no authentication is required, but the victim must visit the page and the control must be permitted to run (user interaction).
Exploitation
Public exploit code exists (Exploit-DB 5460 and 5530, SecurityFocus BID 28820 tagged Exploit), and EPSS is 0.52 (98.9th percentile), indicating a high likelihood of exploitation; the CVE is not listed in CISA KEV.
What to do
- Apply the vendor's guidance or workaround; note that Microsoft stated no security update would be issued for WkImgSrv.dll, so patching may not be available.
- Disable or kill-bit the vulnerable ActiveX control in WkImgSrv.dll via Internet Explorer's ActiveX controls and plug-ins settings.
- Restrict or block the control from running in browsers using Group Policy or the registry kill-bit mechanism.
- Remove or uninstall Microsoft Works 7 and Office 2003/2007 where the control is not required.
- Educate users not to visit untrusted sites and enforce safe browsing practices.
Detection
- Monitor for browser processes loading WkImgSrv.dll or instantiating the WksPictureInterface ActiveX control.
- Hunt for suspicious child processes spawned by browsers (e.g., iexplore.exe) that may indicate code execution.
- Review web proxy or DNS logs for access to known exploit hosts or pages hosting the malicious ActiveX control.
- Check for crash reports or event logs referencing WkImgSrv.dll or browser crashes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-1898 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-1898), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.