Cisco Unity ActiveX Header Active Template Library Remote Code Execution Vulnerability
BID:35847
Info
Cisco Unity ActiveX Header Active Template Library Remote Code Execution Vulnerability
| Bugtraq ID: | 35847 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 28 2009 12:00AM |
| Updated: | Jul 28 2009 09:05PM |
| Credit: | Cisco |
| Vulnerable: |
Cisco Unity 7.0 ES8 Cisco Unity 7.0 Cisco Unity 5.0 ES53 Cisco Unity 5.0 Cisco Unity 4.0 ES161 Cisco Unity 4.0 |
| Not Vulnerable: | |
Discussion
Cisco Unity ActiveX Header Active Template Library Remote Code Execution Vulnerability
Cisco Unity Player is prone to a remote code-execution vulnerability because it was compiled against the Microsoft Active Template Library (ATL). This issue is tracked by Cisco Bug ID CSCta71728.
Remote attackers can exploit this issue to execute arbitrary code with the privileges of the user running the affected application, possibly with SYSTEM-level privileges. Failed exploit attempts will likely result in a denial-of-service condition.
This issue is caused by the vulnerabilities described in Microsoft security advisory 973883 and is related to the following BIDs:
35828 Microsoft Visual Studio Active Template Library COM Object Remote Code Execution Vulnerability
35830 Microsoft Visual Studio Active Template Library NULL String Information Disclosure Vulnerability
35832 Microsoft Visual Studio ATL 'VariantClear()' Remote Code Execution Vulnerability
Cisco Unity Player is prone to a remote code-execution vulnerability because it was compiled against the Microsoft Active Template Library (ATL). This issue is tracked by Cisco Bug ID CSCta71728.
Remote attackers can exploit this issue to execute arbitrary code with the privileges of the user running the affected application, possibly with SYSTEM-level privileges. Failed exploit attempts will likely result in a denial-of-service condition.
This issue is caused by the vulnerabilities described in Microsoft security advisory 973883 and is related to the following BIDs:
35828 Microsoft Visual Studio Active Template Library COM Object Remote Code Execution Vulnerability
35830 Microsoft Visual Studio Active Template Library NULL String Information Disclosure Vulnerability
35832 Microsoft Visual Studio ATL 'VariantClear()' Remote Code Execution Vulnerability
Exploit / POC
Cisco Unity ActiveX Header Active Template Library Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Cisco Unity ActiveX Header Active Template Library Remote Code Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Cisco Unity ActiveX Header Active Template Library Remote Code Execution Vulnerability
References:
References:
- Cisco Security Advisory: Active Template Library (ATL) Vulnerability (Cisco Systems Product Security Incident Response Team
) - Preventing ActiveX Exploits with Cisco Firewall Application Layer Protocol Inspe (Cisco)
- Cisco Security Advisory: Active Template Library (ATL) Vulnerability (Cisco)
- Microsoft Security Advisory (973882): Vulnerabilities in Microsoft Active Templa (Microsoft)
- Microsoft Security Bulletin MS09-034 (Microsoft)
- Microsoft Security Bulletin MS09-035 (Microsoft)