MW6 PDF417 'MW6PDF417.dll' ActiveX Control Multiple Arbitrary File Overwrite Vulnerabilities
BID:31983
Info
MW6 PDF417 'MW6PDF417.dll' ActiveX Control Multiple Arbitrary File Overwrite Vulnerabilities
| Bugtraq ID: | 31983 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-4926 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 29 2008 12:00AM |
| Updated: | Apr 16 2015 05:52PM |
| Credit: | Dr.Pantagon |
| Vulnerable: |
MW6 Technologies PDF417 ActiveX 3.0 1 |
| Not Vulnerable: | |
Discussion
MW6 PDF417 'MW6PDF417.dll' ActiveX Control Multiple Arbitrary File Overwrite Vulnerabilities
MW6 PDF417 ActiveX control is prone to multiple vulnerabilities that let attackers overwrite files with arbitrary, attacker-controlled content.
Successfully exploiting these issues will allow an attacker to corrupt and overwrite arbitrary files on the victim's computer in the context of the vulnerable application using the ActiveX control (typically Internet Explorer).
MW6 PDF417 ActiveX control 3.0.0.1 is vulnerable; other versions may also be affected.
MW6 PDF417 ActiveX control is prone to multiple vulnerabilities that let attackers overwrite files with arbitrary, attacker-controlled content.
Successfully exploiting these issues will allow an attacker to corrupt and overwrite arbitrary files on the victim's computer in the context of the vulnerable application using the ActiveX control (typically Internet Explorer).
MW6 PDF417 ActiveX control 3.0.0.1 is vulnerable; other versions may also be affected.
Exploit / POC
MW6 PDF417 'MW6PDF417.dll' ActiveX Control Multiple Arbitrary File Overwrite Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting victim into viewing a malicious web page.
The following example exploit code is available:
To exploit these issues, an attacker must entice an unsuspecting victim into viewing a malicious web page.
The following example exploit code is available:
Solution / Fix
MW6 PDF417 'MW6PDF417.dll' ActiveX Control Multiple Arbitrary File Overwrite Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
MW6 PDF417 'MW6PDF417.dll' ActiveX Control Multiple Arbitrary File Overwrite Vulnerabilities
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Vendor Homepage (MW6 Technologies)