Microsoft Patches Critical VBA Flaw

Microsoft Patches Critical VBA Flaw

Written By
Dennis Fisher
Dennis Fisher
Sep 3, 2003
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Microsoft Corp. on Wednesday issued a patch for a critical vulnerability in its Visual Basic for Applications SDK, which could allow an attacker to execute arbitrary code on a vulnerable server.

The weakness exists in the way that VBA looks at the properties of documents passed to it when the document is opened by a host application. There is a buffer overrun in this process, which an attacker could exploit to run code.

For the attack to work, a user would have to open a malicious document that the attacker sends. But this could happen with any document format that supports VBA, including Word, Excel or PowerPoint.

VBA is based on the Visual Basic development environment and is used to develop desktop applications and integrate them with existing systems. This vulnerability affects VBA SDK versions 5, 6, 6.2 and 6.3. The patch for this flaw is located here.

Microsoft, based in Redmond, Wash., also released patches for four other less severe vulnerabilities in Access, the WordPerfect converter technology, Word and NetBIOS.

Discuss this in the eWeek forum.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.