Microsoft Works 7 'WkImgSrv.dll' ActiveX Control Remote Code Execution Vulnerability
BID:28820
Info
Microsoft Works 7 'WkImgSrv.dll' ActiveX Control Remote Code Execution Vulnerability
| Bugtraq ID: | 28820 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-1898 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 17 2008 12:00AM |
| Updated: | Jan 13 2011 08:22AM |
| Credit: | Shennan Wang |
| Vulnerable: |
Microsoft WkImgSrv.dll 7.3.616 |
| Not Vulnerable: | |
Discussion
Microsoft Works 7 'WkImgSrv.dll' ActiveX Control Remote Code Execution Vulnerability
Microsoft Works 7 'WkImgSrv.dll' ActiveX control is prone to a remote code-execution vulnerability because it fails to sufficiently verify user-supplied input.
An attacker can exploit this issue to run arbitrary attacker-supplied code in the context of the currently logged-in user. Failed exploits attempts will trigger denial-of-service conditions.
This issue affects Microsoft Works 7 'WkImgSrv.dll' ActiveX control 7.03.0616; other versions may also be vulnerable.
NOTE: This ActiveX control is not marked 'safe for scripting' and would therefore prompt the victim before executing the script. Typically, we would not classify this issue as a security vulnerability. However, given the nature of the issue and the existence of exploit code in the wild, this BID will not be retired so that a record of the issue can be maintained.
Microsoft Works 7 'WkImgSrv.dll' ActiveX control is prone to a remote code-execution vulnerability because it fails to sufficiently verify user-supplied input.
An attacker can exploit this issue to run arbitrary attacker-supplied code in the context of the currently logged-in user. Failed exploits attempts will trigger denial-of-service conditions.
This issue affects Microsoft Works 7 'WkImgSrv.dll' ActiveX control 7.03.0616; other versions may also be vulnerable.
NOTE: This ActiveX control is not marked 'safe for scripting' and would therefore prompt the victim before executing the script. Typically, we would not classify this issue as a security vulnerability. However, given the nature of the issue and the existence of exploit code in the wild, this BID will not be retired so that a record of the issue can be maintained.
Exploit / POC
Microsoft Works 7 'WkImgSrv.dll' ActiveX Control Remote Code Execution Vulnerability
An attacker can exploit this issue by enticing an unsuspecting victim to view a malicious HTML page.
UPDATE (May 6, 2008): The DeepSight Threat Analysis Team discovered that this issue is actively being exploited in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof of concept and exploit are available:
An attacker can exploit this issue by enticing an unsuspecting victim to view a malicious HTML page.
UPDATE (May 6, 2008): The DeepSight Threat Analysis Team discovered that this issue is actively being exploited in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof of concept and exploit are available:
Solution / Fix
Microsoft Works 7 'WkImgSrv.dll' ActiveX Control Remote Code Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
NOTE: This ActiveX control is not marked 'safe for scripting' and would therefore prompt the victim before executing the script. Typically, we would not classify this issue as a security vulnerability. However, given the nature of the issue and the existence of exploit code in the wild, this BID will not be retired so that a record of the issue can be maintained.
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
NOTE: This ActiveX control is not marked 'safe for scripting' and would therefore prompt the victim before executing the script. Typically, we would not classify this issue as a security vulnerability. However, given the nature of the issue and the existence of exploit code in the wild, this BID will not be retired so that a record of the issue can be maintained.
References
Microsoft Works 7 'WkImgSrv.dll' ActiveX Control Remote Code Execution Vulnerability
References:
References: