DateV 'DVBSExeCall.ocx' ActiveX Control Remote Command Execution Vulnerability
BID:38415
Info
DateV 'DVBSExeCall.ocx' ActiveX Control Remote Command Execution Vulnerability
| Bugtraq ID: | 38415 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-0689 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 25 2010 12:00AM |
| Updated: | Apr 13 2015 09:02PM |
| Credit: | Nikolas Sotiriu |
| Vulnerable: |
DATEV DVBSExeCall.ocx 1.0.0.1 DATEV DVBSExeCall.ocx 1.0 |
| Not Vulnerable: | |
Discussion
DateV 'DVBSExeCall.ocx' ActiveX Control Remote Command Execution Vulnerability
The DateV 'DVBSExeCall.ocx' ActiveX control is prone to a remote command-execution vulnerability.
An attacker can exploit this issue by enticing an unsuspecting user to view a malicious webpage.
Successful exploits will allow the attacker to execute arbitrary commands within the context of the application that uses the ActiveX control (typically Internet Explorer).
The DateV 'DVBSExeCall.ocx' ActiveX control is prone to a remote command-execution vulnerability.
An attacker can exploit this issue by enticing an unsuspecting user to view a malicious webpage.
Successful exploits will allow the attacker to execute arbitrary commands within the context of the application that uses the ActiveX control (typically Internet Explorer).
Exploit / POC
DateV 'DVBSExeCall.ocx' ActiveX Control Remote Command Execution Vulnerability
The following video demonstrates a proof of concept:
http://sotiriu.de/demos/videos/nso-2010-003.html
The following video demonstrates a proof of concept:
http://sotiriu.de/demos/videos/nso-2010-003.html
Solution / Fix
DateV 'DVBSExeCall.ocx' ActiveX Control Remote Command Execution Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
DateV 'DVBSExeCall.ocx' ActiveX Control Remote Command Execution Vulnerability
References:
References:
- DateV 1.0 Vendor Advisory (DateV)
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Vendor Homepage (DATEV)