EasyMail Objects 'emimap4.dll' ActiveX Control Remote Code Execution Vulnerability
BID:36409
Info
EasyMail Objects 'emimap4.dll' ActiveX Control Remote Code Execution Vulnerability
| Bugtraq ID: | 36409 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 15 2009 12:00AM |
| Updated: | Jul 28 2010 07:25PM |
| Credit: | Francis Provencher |
| Vulnerable: |
Quiksoft EasyMail Objects 'emmailstore.dll' 6.0.2.0 Giant Company Spam Inspector 4.0.354 |
| Not Vulnerable: | |
Discussion
EasyMail Objects 'emimap4.dll' ActiveX Control Remote Code Execution Vulnerability
EasyMail Objects ActiveX control is prone to a remote code-execution vulnerability because the application fails to properly sanitize user-supplied data.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application (typically Internet Explorer) using the ActiveX control. Failed exploit attempts likely result in denial-of-service conditions.
EasyMail Objects 6.0.2.0 is vulnerable; other versions may also be affected.
Spam Inspector 4.0.354 is vulnerable.
EasyMail Objects ActiveX control is prone to a remote code-execution vulnerability because the application fails to properly sanitize user-supplied data.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application (typically Internet Explorer) using the ActiveX control. Failed exploit attempts likely result in denial-of-service conditions.
EasyMail Objects 6.0.2.0 is vulnerable; other versions may also be affected.
Spam Inspector 4.0.354 is vulnerable.
Exploit / POC
EasyMail Objects 'emimap4.dll' ActiveX Control Remote Code Execution Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to view a maliciously crafted webpage.
The following proof of concept is available:
To exploit this issue, an attacker must entice an unsuspecting user to view a maliciously crafted webpage.
The following proof of concept is available:
Solution / Fix
EasyMail Objects 'emimap4.dll' ActiveX Control Remote Code Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
EasyMail Objects 'emimap4.dll' ActiveX Control Remote Code Execution Vulnerability
References:
References:
- EasyMail Objects Homepage (Quiksoft)
- Microsoft Knowledge Base Article 240797 (Microsoft)