Akamai Download Manager ActiveX Control Remote Code Execution Vulnerability
BID:28993
Info
Akamai Download Manager ActiveX Control Remote Code Execution Vulnerability
| Bugtraq ID: | 28993 |
| Class: | Unknown |
| CVE: |
CVE-2007-6339 CVE-2008-1770 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 30 2008 12:00AM |
| Updated: | Feb 10 2009 09:48PM |
| Credit: | iDefense Labs |
| Vulnerable: |
Akamai Akamai Download Manager 2.2.3.5 Akamai Akamai Download Manager 2.2.1.0 Akamai Akamai Download Manager 2.2.0.0 |
| Not Vulnerable: |
Akamai Akamai Download Manager 2.2.3 7 |
Discussion
Akamai Download Manager ActiveX Control Remote Code Execution Vulnerability
Akamai Download Manager is prone to a remote code-execution vulnerability.
Exploiting this issue allows remote attackers to execute arbitrary code in the context of applications using the affected ActiveX control and to compromise affected computers.
This issue affects versions prior to Download Manager 2.2.3.7.
Akamai Download Manager is prone to a remote code-execution vulnerability.
Exploiting this issue allows remote attackers to execute arbitrary code in the context of applications using the affected ActiveX control and to compromise affected computers.
This issue affects versions prior to Download Manager 2.2.3.7.
Exploit / POC
Akamai Download Manager ActiveX Control Remote Code Execution Vulnerability
The following proof of concept is available:
The following proof of concept is available:
Solution / Fix
Akamai Download Manager ActiveX Control Remote Code Execution Vulnerability
Solution:
The vendor has released Download Manager 2.2.5.5 to resolve this issue; please see the references for details.
Akamai Akamai Download Manager 2.2.0.0
Akamai Akamai Download Manager 2.2.1.0
Solution:
The vendor has released Download Manager 2.2.5.5 to resolve this issue; please see the references for details.
Akamai Akamai Download Manager 2.2.0.0
-
Akamai Akamai Download Manager
http://dlm.tools.akamai.com/tools/upgrade.html
Akamai Akamai Download Manager 2.2.1.0
-
Akamai Akamai Download Manager
http://dlm.tools.akamai.com/tools/upgrade.html
References
Akamai Download Manager ActiveX Control Remote Code Execution Vulnerability
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Vendor Homepage (Akamai)
- Akamai Download Manager File Downloaded To Arbitrary Location Vulnerability (cocoruder
) - Akamai Technologies Security Advisory 2008-0001 (Download Manager) (Akamai Security Team
) - iDefense Security Advisory 04.30.08: Akamai Download Manager Arbitrary Program E (iDefense Labs
) - Akamai Download Manager Arbitrary Program Execution Vulnerability (iDefense)
- Microsoft Security Advisory 960715 (Microsoft)