Microsoft PicturePusher 'PipPPush.dll' ActiveX Control Arbitrary File Download Vulnerability
BID:31632
Info
Microsoft PicturePusher 'PipPPush.dll' ActiveX Control Arbitrary File Download Vulnerability
| Bugtraq ID: | 31632 |
| Class: | Design Error |
| CVE: |
CVE-2008-4493 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 08 2008 12:00AM |
| Updated: | Apr 16 2015 05:52PM |
| Credit: | Nine:Situations:Group::pyrokinesis |
| Vulnerable: |
Microsoft PipPPush.dll 7.0.709 Microsoft Digital Image Suite 2006 |
| Not Vulnerable: | |
Discussion
Microsoft PicturePusher 'PipPPush.dll' ActiveX Control Arbitrary File Download Vulnerability
Microsoft PicturePusher ActiveX control in 'PipPPush.dll' is prone to a vulnerability that lets attackers download arbitrary files.
Attackers may exploit this issue by enticing victims into visiting a maliciously crafted webpage.
Successful exploits will allow remote attackers to download files from arbitrary locations to the affected computer.
The affected ActiveX control may be a component of Microsoft Digital Image 2006 Starter Edition.
'PipPPush.dll' 7.00.0709 is vulnerable; other versions may also be affected.
Microsoft PicturePusher ActiveX control in 'PipPPush.dll' is prone to a vulnerability that lets attackers download arbitrary files.
Attackers may exploit this issue by enticing victims into visiting a maliciously crafted webpage.
Successful exploits will allow remote attackers to download files from arbitrary locations to the affected computer.
The affected ActiveX control may be a component of Microsoft Digital Image 2006 Starter Edition.
'PipPPush.dll' 7.00.0709 is vulnerable; other versions may also be affected.
Exploit / POC
Microsoft PicturePusher 'PipPPush.dll' ActiveX Control Arbitrary File Download Vulnerability
Attackers can exploit this issue by enticing victims into visiting a maliciously crafted webpage.
The following exploit code is available:
Attackers can exploit this issue by enticing victims into visiting a maliciously crafted webpage.
The following exploit code is available:
Solution / Fix
Microsoft PicturePusher 'PipPPush.dll' ActiveX Control Arbitrary File Download Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Microsoft PicturePusher 'PipPPush.dll' ActiveX Control Arbitrary File Download Vulnerability
References:
References:
- Digital Image Starter Edition 2006 Homepage (Microsoft)
- Microsoft Knowledge Base Article 240797 (Microsoft)