Groove Networks Groove Virtual Office COM Object Security Bypass Vulnerability
BID:13685
Info
Groove Networks Groove Virtual Office COM Object Security Bypass Vulnerability
| Bugtraq ID: | 13685 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | May 19 2005 12:00AM |
| Updated: | May 19 2005 12:00AM |
| Credit: | This issue was reported by US-CERT. |
| Vulnerable: |
Groove Networks Workspace 2.5 Groove Networks Workspace 2.0 Groove Networks Virtual Office 3.1 a Groove Networks Virtual Office 3.1 Groove Networks Virtual Office 3.0 |
| Not Vulnerable: |
Groove Networks Workspace 2.5 n build 1871 Groove Networks Virtual Office 3.1 build 2338 Groove Networks Virtual Office 3.1 a build 2364 |
Discussion
Groove Networks Groove Virtual Office COM Object Security Bypass Vulnerability
Groove Virtual Office is prone to a security bypass vulnerability with regards to COM objects. Due to a failure in the application an attacker may be able to bypass the security restrictions on COM objects and execute arbitrary code.
This issue has been addressed in Groove Virtual Office 3.1 build 2338, 3.1a build 2364, and Groove Workspace Version 2.5n build 1871.
Groove Virtual Office is prone to a security bypass vulnerability with regards to COM objects. Due to a failure in the application an attacker may be able to bypass the security restrictions on COM objects and execute arbitrary code.
This issue has been addressed in Groove Virtual Office 3.1 build 2338, 3.1a build 2364, and Groove Workspace Version 2.5n build 1871.
Exploit / POC
Groove Networks Groove Virtual Office COM Object Security Bypass Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Groove Networks Groove Virtual Office COM Object Security Bypass Vulnerability
Solution:
The vendor has released updates to address this issue. Updates are available from the following locations:
3.x releases:
http://www.groove.net/update
2.x releases:
http://www.groove.net/archive
Solution:
The vendor has released updates to address this issue. Updates are available from the following locations:
3.x releases:
http://www.groove.net/update
2.x releases:
http://www.groove.net/archive
References
Groove Networks Groove Virtual Office COM Object Security Bypass Vulnerability
References:
References:
- Home Page (Groove Networks)
- Vulnerability Note VU#155610 - Groove Virtual Office COM objects (US-CERT)