Acer LunchApp ActiveX Control Remote Code Execution Vulnerability
BID:36068
Info
Acer LunchApp ActiveX Control Remote Code Execution Vulnerability
| Bugtraq ID: | 36068 |
| Class: | Design Error |
| CVE: |
CVE-2009-2627 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 18 2009 12:00AM |
| Updated: | Aug 21 2009 03:56PM |
| Credit: | Michael Costa of Crosshair Information Technology & Security LLC. |
| Vulnerable: |
Acer AcerCtrls.APlunch ActiveX Control 0 |
| Not Vulnerable: | |
Discussion
Acer LunchApp ActiveX Control Remote Code Execution Vulnerability
Acer LunchApp ActiveX Control is prone to a remote code-execution vulnerability. This control is identified by the following CLSID:
3895DD35-7573-11D2-8FED-00606730D3AA
An attacker can exploit this issue to execute arbitrary code in the context of the application using the vulnerable ActiveX control (typically Internet Explorer).
Acer LunchApp ActiveX Control is prone to a remote code-execution vulnerability. This control is identified by the following CLSID:
3895DD35-7573-11D2-8FED-00606730D3AA
An attacker can exploit this issue to execute arbitrary code in the context of the application using the vulnerable ActiveX control (typically Internet Explorer).
Exploit / POC
Acer LunchApp ActiveX Control Remote Code Execution Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into viewing a malicious webpage.
To exploit this issue, an attacker must entice an unsuspecting victim into viewing a malicious webpage.
Solution / Fix
Acer LunchApp ActiveX Control Remote Code Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Acer LunchApp ActiveX Control Remote Code Execution Vulnerability
References:
References: