AOL SuperBuddy ActiveX Control Remote Code Execution Vulnerability
BID:36580
Info
AOL SuperBuddy ActiveX Control Remote Code Execution Vulnerability
| Bugtraq ID: | 36580 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 01 2009 12:00AM |
| Updated: | Oct 02 2009 11:50PM |
| Credit: | Nine:Situations:Group::Trotzkista |
| Vulnerable: |
AOL AOL 9.1 |
| Not Vulnerable: | |
Discussion
AOL SuperBuddy ActiveX Control Remote Code Execution Vulnerability
AOL SuperBuddy ActiveX control is prone to a remote code-execution vulnerability caused by a memory-corruption error.
An attacker can exploit this issue to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
AOL 9.1 is vulnerable; other versions may also be affected.
AOL SuperBuddy ActiveX control is prone to a remote code-execution vulnerability caused by a memory-corruption error.
An attacker can exploit this issue to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
AOL 9.1 is vulnerable; other versions may also be affected.
Exploit / POC
AOL SuperBuddy ActiveX Control Remote Code Execution Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
AOL SuperBuddy ActiveX Control Remote Code Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
AOL SuperBuddy ActiveX Control Remote Code Execution Vulnerability
References:
References: