Overview
The Microsoft Office Web Components Spreadsheet ActiveX controls (OWC10 and OWC11) contain a vulnerability that may allow an attacker to take control of a vulnerable system.
Description
The Office Web Components Spreadsheet ActiveX control contains a code execution vulnerability. Public reports indicate that this vulnerability is being actively exploited. Per the MSRC blog, the following products may install the affected control on a system:  | 
Impact
A remote attacker may be able to take control of a vulnerable system.  | 
Solution
Install the updates described in Microsoft Security Bulletin MS09-043.  | 
Disable the Office Web Components Spreadsheet ActiveX controls in Internet Explorer  | 
Vendor Information
CVSS Metrics
| Group | Score | Vector | 
|---|---|---|
| Base | 0 | AV:--/AC:--/Au:--/C:--/I:--/A:-- | 
| Temporal | 0 | E:ND/RL:ND/RC:ND | 
| Environmental | 0 | CDP:ND/TD:ND/CR:ND/IR:ND/AR:ND | 
References
- http://www.microsoft.com/technet/security/advisory/973472.mspx
 - http://blogs.technet.com/msrc/archive/2009/07/13/microsoft-security-advisory-973472-released.aspx
 - http://blogs.technet.com/srd/archive/2009/07/13/more-information-about-the-office-web-components-activex-vulnerability.aspx
 - http://www.microsoft.com/technet/security/bulletin/ms09-043.mspx
 - http://support.microsoft.com/kb/240797
 
Acknowledgements
Thanks to Microsoft for information that was used in this report.
This document was written by Ryan Giobbi.
Other Information
| CVE IDs: | CVE-2009-1136 | 
| Severity Metric: | 44.04 | 
| Date Public: | 2009-07-13 | 
| Date First Published: | 2009-07-15 | 
| Date Last Updated: | 2009-08-27 05:40 UTC | 
| Document Revision: | 23 |