Welcome to the Virus Encyclopedia of Panda Security.
|Alias:||Vulnerability in Microsoft Jet Database Engine Could Allow Remote Code Execution|
It is a critical vulnerability in the Jet 4.0 Database Engine, which allows hackers to gain remote control of the affected computer with the same privileges as the logged-on user.
|First detected on:||May 14, 2008|
|Detection updated on:||May 14, 2008|
MS08-028 is not categorized as virus, worm, Trojan or backdoor. It is a critical vulnerability in the Jet 4.0 Database Engine on Windows 2003/XP/2000 computers, which allows arbitrary code to be remotely executed in the vulnerable computer.
If exploited successfully, MS08-028 allows hackers to gain remote control of the affected computer with the same privileges as the logged-on user. If this user had administrator rights, the hacker could take complete control of the system: create, modify or delete files, install programs, create new user accounts, etc.
MS08-028 is exploited by sending a specially crafted jet file via email and enticing users into opening it or by hosting a specially crafted jet file in a web page and entincing users into visiting it.
If you have the Jet Database Engine installed on your Windows 2003/XP/2000 computer, it is recommended to download and apply the security patch for this vulnerability. Click here to access the web page for downloading the patch.