Unrated severityNVD Advisory· Published Apr 21, 2008· Updated Apr 23, 2026
CVE-2008-1898
CVE-2008-1898
Description
A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and 2007, allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via an invalid WksPictureInterface property value, which triggers an improper function call.
Affected products
3Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- archives.neohapsis.com/archives/fulldisclosure/2008-05/0029.htmlnvdExploit
- www.securityfocus.com/bid/28820nvdExploit
- blogs.technet.com/swi/archive/2008/06/05/why-there-wont-be-a-security-update-for-wkimgsrv-dll.aspxnvd
- www.securityfocus.com/archive/1/491027/100/0/threadednvd
- exchange.xforce.ibmcloud.com/vulnerabilities/41876nvd
- www.exploit-db.com/exploits/5460nvd
- www.exploit-db.com/exploits/5530nvd
News mentions
0No linked articles in our index yet.