Vulnerability record · CVE-2008-2463 · published 7 July 2008
CVE-2008-2463: Microsoft Office Snapshot Viewer ActiveX control arbitrary file download
Microsoft · Office Snapshot Viewer Activex
The Microsoft Office Snapshot Viewer ActiveX control (snapview.ocx 10.0.5529.0), shipped standalone and with Access 2000 through 2003, lets a remote attacker download arbitrary files to a client machine via a crafted HTML document or e-mail message. The flaw likely involves the SnapshotPath and CompressedPath properties and the PrintSnapshot method, and the downloaded file can be placed in a Startup folder to gain code execution.
Description
The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snapshot Viewer and Microsoft Office Access 2000 through 2003, allows remote attackers to download arbitrary files to a client machine via a crafted HTML document or e-mail message, probably involving use of the SnapshotPath and CompressedPath properties and the PrintSnapshot method. NOTE: this can be leveraged for code execution by writing to a Startup folder.
AV:N/AC:M/Au:N/C:P/I:P/A:P
Automated analysis
high priorityThe flaw allows unauthenticated remote file write and code execution, public exploit code exists, and EPSS is very high, though the control is legacy and not in KEV.
What it is
The Microsoft Office Snapshot Viewer ActiveX control (snapview.ocx 10.0.5529.0), shipped standalone and with Access 2000 through 2003, lets a remote attacker download arbitrary files to a client machine via a crafted HTML document or e-mail message. The flaw likely involves the SnapshotPath and CompressedPath properties and the PrintSnapshot method, and the downloaded file can be placed in a Startup folder to gain code execution.
Impact
An attacker can write arbitrary files to the victim's machine and, by targeting a Startup folder, achieve code execution under the user's context. This gives full control of the affected host without any prior authentication.
Attack surface
Reached over the network through a crafted HTML page or e-mail message that instantiates the ActiveX control in a browser. No authentication is required, but the victim must view the page or message and the control must be permitted to run, so user interaction is needed.
Exploitation
Not listed in CISA KEV, but EPSS is 0.59125 (99th percentile) and public exploit code exists in Exploit-DB (6124), indicating active exploitation is likely.
What to do
- Apply the Microsoft security advisory 955179 fix or upgrade to a non-vulnerable version of the Snapshot Viewer and Office.
- Set the kill bit for the Snapshot Viewer ActiveX control (CLSID) in Internet Explorer and other browsers that honor it.
- Restrict or block the control via Group Policy or browser ActiveX allow-lists.
- Block or filter e-mail and web content that instantiates the control, and disable ActiveX in untrusted zones.
- Remove the standalone Snapshot Viewer from systems that do not require it.
Detection
- Monitor for snapview.ocx or the Snapshot Viewer CLSID being instantiated in browser or e-mail client processes.
- Alert on file writes to Startup folders originating from browser or Office processes.
- Search endpoint logs for unexpected .ocx loads or new files in user Startup directories.
- Review proxy and mail logs for HTML or messages referencing SnapshotPath, CompressedPath, or PrintSnapshot.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-2463 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-2463), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.