← Vulnerability feed

Vulnerability record · CVE-2008-2463 · published 7 July 2008

CVE-2008-2463: Microsoft Office Snapshot Viewer ActiveX control arbitrary file download

Microsoft · Office Snapshot Viewer Activex

The Microsoft Office Snapshot Viewer ActiveX control (snapview.ocx 10.0.5529.0), shipped standalone and with Access 2000 through 2003, lets a remote attacker download arbitrary files to a client machine via a crafted HTML document or e-mail message. The flaw likely involves the SnapshotPath and CompressedPath properties and the PrintSnapshot method, and the downloaded file can be placed in a Startup folder to gain code execution.

6.8 CVSS 2.0 Medium EPSS 59% · top 0.9% CWE-94 · Code injection
6.8CVSS 2.0 base score
59%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
24References
16 Jun 2026Last modified by NVD

Description

The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snapshot Viewer and Microsoft Office Access 2000 through 2003, allows remote attackers to download arbitrary files to a client machine via a crafted HTML document or e-mail message, probably involving use of the SnapshotPath and CompressedPath properties and the PrintSnapshot method. NOTE: this can be leveraged for code execution by writing to a Startup folder.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityThe flaw allows unauthenticated remote file write and code execution, public exploit code exists, and EPSS is very high, though the control is legacy and not in KEV.

What it is

The Microsoft Office Snapshot Viewer ActiveX control (snapview.ocx 10.0.5529.0), shipped standalone and with Access 2000 through 2003, lets a remote attacker download arbitrary files to a client machine via a crafted HTML document or e-mail message. The flaw likely involves the SnapshotPath and CompressedPath properties and the PrintSnapshot method, and the downloaded file can be placed in a Startup folder to gain code execution.

Impact

An attacker can write arbitrary files to the victim's machine and, by targeting a Startup folder, achieve code execution under the user's context. This gives full control of the affected host without any prior authentication.

Attack surface

Reached over the network through a crafted HTML page or e-mail message that instantiates the ActiveX control in a browser. No authentication is required, but the victim must view the page or message and the control must be permitted to run, so user interaction is needed.

Exploitation

Not listed in CISA KEV, but EPSS is 0.59125 (99th percentile) and public exploit code exists in Exploit-DB (6124), indicating active exploitation is likely.

What to do

  • Apply the Microsoft security advisory 955179 fix or upgrade to a non-vulnerable version of the Snapshot Viewer and Office.
  • Set the kill bit for the Snapshot Viewer ActiveX control (CLSID) in Internet Explorer and other browsers that honor it.
  • Restrict or block the control via Group Policy or browser ActiveX allow-lists.
  • Block or filter e-mail and web content that instantiates the control, and disable ActiveX in untrusted zones.
  • Remove the standalone Snapshot Viewer from systems that do not require it.

Detection

  • Monitor for snapview.ocx or the Snapshot Viewer CLSID being instantiated in browser or e-mail client processes.
  • Alert on file writes to Startup folders originating from browser or Office processes.
  • Search endpoint logs for unexpected .ocx loads or new files in user Startup directories.
  • Review proxy and mail logs for HTML or messages referencing SnapshotPath, CompressedPath, or PrintSnapshot.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-2463 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-65660Microsoft sharepoint server code injection vulnerabilityImproper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.KEVEPSS 2.1%9.8CVE-2026-60004Gitea diffpatch API code injection enables remote code executionGitea before 1.27.1 allows remote code execution through the diffpatch API by way of Git hook installation. The flaw is a code injection issue (CWE-9…KEVEPSS 24%analysed9.5CVE-2026-72530TrueConf Server sandbox breakout via crafted script code injectionTrueConf Server versions 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5 and earlier allow a remote unauthenticated attacker to break o…KEVEPSS 1.7%analysed9.4CVE-2025-62593Ray browser-based RCE via insufficient User-Agent guardRay, an AI compute engine, contains a critical remote code execution flaw before version 2.52.0. Its defense against browser-based attacks relies on …KEVEPSS 62%analysed9.8CVE-2026-9198Langflow auto_login and code validation chain enables unauthenticated RCEIBM Langflow OSS 1.0.0 through 1.10.0 exposes /api/v1/auto_login, which mints SUPERUSER tokens to any network caller, and /api/v1/validate/code, whic…KEVEPSS 29%analysed7.2CVE-2026-15410SonicWall SMA1000 AMC code injection allows OS command executionThe SMA1000 Appliance Management Console (AMC) contains a post-authentication code injection flaw (CWE-94) that, under specific conditions, lets an a…KEVEPSS 12%analysed9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed8.8CVE-2026-34197Apache ActiveMQ Jolokia JMX bridge code injection via broker config URIApache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ with a default policy that allows exec operations on all org.apache.acti…KEVEPSS 15%analysed

Source: NIST National Vulnerability Database (record CVE-2008-2463), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.