Comodo AntiVirus 'ExecuteStr()' ActiveX Control Arbitrary Command Execution Vulnerability
BID:27424
Info
Comodo AntiVirus 'ExecuteStr()' ActiveX Control Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 27424 |
| Class: | Design Error |
| CVE: |
CVE-2008-0470 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 23 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | Krystian Kloskowski (h07) is credited with the discovery of this vulnerability. |
| Vulnerable: |
Comodo AntiVirus 2.0 |
| Not Vulnerable: | |
Discussion
Comodo AntiVirus 'ExecuteStr()' ActiveX Control Arbitrary Command Execution Vulnerability
An ActiveX control in Comodo AntiVirus is prone to a vulnerability that lets attackers execute arbitrary commands.
Successfully exploiting this issue allows remote attackers to execute arbitrary commands in the context of the application using the ActiveX control (typically Internet Explorer).
Comodo AntiVirus 2.0 is vulnerable to this issue; other versions may also be affected.
An ActiveX control in Comodo AntiVirus is prone to a vulnerability that lets attackers execute arbitrary commands.
Successfully exploiting this issue allows remote attackers to execute arbitrary commands in the context of the application using the ActiveX control (typically Internet Explorer).
Comodo AntiVirus 2.0 is vulnerable to this issue; other versions may also be affected.
Exploit / POC
Comodo AntiVirus 'ExecuteStr()' ActiveX Control Arbitrary Command Execution Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to access a malicious webpage.
The following exploit code is available:
To exploit this issue, an attacker must entice an unsuspecting user to access a malicious webpage.
The following exploit code is available:
Solution / Fix
Comodo AntiVirus 'ExecuteStr()' ActiveX Control Arbitrary Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Comodo AntiVirus 'ExecuteStr()' ActiveX Control Arbitrary Command Execution Vulnerability
References:
References:
- Comodo Homepage (Comodo)
- Microsoft Knowledge Base Article 240797 (Microsoft)