RETIRED: Mircrosoft Rich TextBox Control 'richtx32.ocx' ActiveX Insecure Method Vulnerability
BID:27201
Info
RETIRED: Mircrosoft Rich TextBox Control 'richtx32.ocx' ActiveX Insecure Method Vulnerability
| Bugtraq ID: | 27201 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0237 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 09 2008 12:00AM |
| Updated: | May 12 2015 07:49PM |
| Credit: | shinnai is credited with the discovery of this vulnerability. |
| Vulnerable: |
Microsoft Rich TextBox Control 6.0 |
| Not Vulnerable: | |
Discussion
RETIRED: Mircrosoft Rich TextBox Control 'richtx32.ocx' ActiveX Insecure Method Vulnerability
Mircrosoft Rich TextBox Control is prone to a vulnerability that allows attackers to create or overwrite arbitrary data with the privileges of the application using the control (typically Internet Explorer).
Successful exploits will compromise affected computers or cause denial-of-service conditions; other attacks are possible.
This issue affects 'richtx32.ocx' 6.1.97.82; other versions may also be affected.
NOTE: This BID is being retired because the issue is not exploitable. The ActiveX control is not marked 'Safe for Scripting'.
Mircrosoft Rich TextBox Control is prone to a vulnerability that allows attackers to create or overwrite arbitrary data with the privileges of the application using the control (typically Internet Explorer).
Successful exploits will compromise affected computers or cause denial-of-service conditions; other attacks are possible.
This issue affects 'richtx32.ocx' 6.1.97.82; other versions may also be affected.
NOTE: This BID is being retired because the issue is not exploitable. The ActiveX control is not marked 'Safe for Scripting'.
Exploit / POC
RETIRED: Mircrosoft Rich TextBox Control 'richtx32.ocx' ActiveX Insecure Method Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to view a specially crafted web document.
The following exploit code is available:
To exploit this issue, an attacker must entice an unsuspecting user to view a specially crafted web document.
The following exploit code is available:
Solution / Fix
RETIRED: Mircrosoft Rich TextBox Control 'richtx32.ocx' ActiveX Insecure Method Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
RETIRED: Mircrosoft Rich TextBox Control 'richtx32.ocx' ActiveX Insecure Method Vulnerability
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- RichTextBox Control Overview (Windows Forms) (Microsoft)