SAP EnjoySAP KWEdit.DLL ActiveX Control Stack Buffer Overflow Vulnerability
BID:24772
Info
SAP EnjoySAP KWEdit.DLL ActiveX Control Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 24772 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-3605 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2007 12:00AM |
| Updated: | Apr 16 2015 06:11PM |
| Credit: | Mark Litchfield is credited with the discovery of these issues. |
| Vulnerable: |
SAP EnjoySAP 0 |
| Not Vulnerable: | |
Discussion
SAP EnjoySAP KWEdit.DLL ActiveX Control Stack Buffer Overflow Vulnerability
EnjoySAP is prone to a stack-based buffer-overflow vulnerability because the software fails to adequately check boundaries on data supplied to an ActiveX control method.
An attacker can exploit this issue to execute arbitrary code in the context of a user running the application. Failed attempts will likely result in denial-of-service conditions.
EnjoySAP is prone to a stack-based buffer-overflow vulnerability because the software fails to adequately check boundaries on data supplied to an ActiveX control method.
An attacker can exploit this issue to execute arbitrary code in the context of a user running the application. Failed attempts will likely result in denial-of-service conditions.
Exploit / POC
SAP EnjoySAP KWEdit.DLL ActiveX Control Stack Buffer Overflow Vulnerability
To exploit these issues, an attacker must entice an unsuspecting user to view a malicious webpage.
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code has been made available:
To exploit these issues, an attacker must entice an unsuspecting user to view a malicious webpage.
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code has been made available:
Solution / Fix
SAP EnjoySAP KWEdit.DLL ActiveX Control Stack Buffer Overflow Vulnerability
Solution:
The vendor has released fixes to address this issue. Please contact the vendor for information on how to obtain and apply these fixes.
Solution:
The vendor has released fixes to address this issue. Please contact the vendor for information on how to obtain and apply these fixes.
References
SAP EnjoySAP KWEdit.DLL ActiveX Control Stack Buffer Overflow Vulnerability
References:
References:
- SAP Homepage (SAP)
- EnjoySAP, SAP GUI for Windows - Stack Overflow (NGS Software Insight Security Research)