EMC Captiva PixTools Distributed Imaging ActiveX Control Multiple Insecure Method Vulnerabilities
BID:36566
Info
EMC Captiva PixTools Distributed Imaging ActiveX Control Multiple Insecure Method Vulnerabilities
| Bugtraq ID: | 36566 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 01 2009 12:00AM |
| Updated: | Dec 09 2009 04:34PM |
| Credit: | shinnai |
| Vulnerable: |
EMC Pixtool Distributed Imaging 2.2 EMC PDIControl.dll 2.2.3160 .0 EMC Captiva PixTools 2.2 EMC Captiva eInput 2.1 EMC Captiva eInput 2.0 EMC Captiva eInput 1.1 |
| Not Vulnerable: |
EMC Pixtool Distributed Imaging 2.2.3168.0 EMC Captiva eInput 2.2.0.182 EMC Captiva eInput 2.1.0.85 EMC Captiva eInput 1.1.0.3075 |
Discussion
EMC Captiva PixTools Distributed Imaging ActiveX Control Multiple Insecure Method Vulnerabilities
The EMC Captiva PixTools Distributed Imaging ActiveX control is prone to multiple insecure-method vulnerabilities that affect the PDIControl.PDI.1 ActiveX control (PDIControl.dll).
Successfully exploiting these issues allows remote attackers to create or overwrite arbitrary local files, which may lead to arbitrary code execution.
PDIControl.dll 2.2.3160.0 is vulnerable; other versions may also be affected.
The EMC Captiva PixTools Distributed Imaging ActiveX control is prone to multiple insecure-method vulnerabilities that affect the PDIControl.PDI.1 ActiveX control (PDIControl.dll).
Successfully exploiting these issues allows remote attackers to create or overwrite arbitrary local files, which may lead to arbitrary code execution.
PDIControl.dll 2.2.3160.0 is vulnerable; other versions may also be affected.
Exploit / POC
EMC Captiva PixTools Distributed Imaging ActiveX Control Multiple Insecure Method Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting user to view a malicious web document.
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit is available:
To exploit these issues, an attacker must entice an unsuspecting user to view a malicious web document.
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit is available:
Solution / Fix
EMC Captiva PixTools Distributed Imaging ActiveX Control Multiple Insecure Method Vulnerabilities
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
EMC Captiva PixTools Distributed Imaging ActiveX Control Multiple Insecure Method Vulnerabilities
References:
References: