Authentium Command On Demand ActiveX Control Multiple Buffer Overflow Vulnerabilities
BID:38544
Info
Authentium Command On Demand ActiveX Control Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 38544 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 04 2010 12:00AM |
| Updated: | Mar 04 2010 12:00AM |
| Credit: | Nikolas Sotiriu |
| Vulnerable: |
Authentium CSS Web Installer 1.4.9508 .605 Authentium Command On Demand Online Scan 0 |
| Not Vulnerable: | |
Discussion
Authentium Command On Demand ActiveX Control Multiple Buffer Overflow Vulnerabilities
The CSS Web Installer ActiveX control in Authentium Command On Demand Online scanner is prone to multiple buffer-overflow vulnerabilities.
An attacker can exploit these issues by enticing a victim to view a malicious webpage. Successful exploits will allow the attacker to execute arbitrary code within the context of the application that uses the ActiveX control (typically Internet Explorer). Failed exploit attempts will result in a denial-of-service condition.
Command On Demand CSS Web Installer ActiveX 1.4.9508.605 is vulnerable; other versions may also be affected.
Note: Reports indicate that the vendor no longer supports this product; vendor patches are not expected to be released.
The CSS Web Installer ActiveX control in Authentium Command On Demand Online scanner is prone to multiple buffer-overflow vulnerabilities.
An attacker can exploit these issues by enticing a victim to view a malicious webpage. Successful exploits will allow the attacker to execute arbitrary code within the context of the application that uses the ActiveX control (typically Internet Explorer). Failed exploit attempts will result in a denial-of-service condition.
Command On Demand CSS Web Installer ActiveX 1.4.9508.605 is vulnerable; other versions may also be affected.
Note: Reports indicate that the vendor no longer supports this product; vendor patches are not expected to be released.
Exploit / POC
Authentium Command On Demand ActiveX Control Multiple Buffer Overflow Vulnerabilities
The following exploit code is available:
The following exploit code is available:
Solution / Fix
Authentium Command On Demand ActiveX Control Multiple Buffer Overflow Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Authentium Command On Demand ActiveX Control Multiple Buffer Overflow Vulnerabilities
References:
References:
- Authentium Homepage (Authentium)
- Microsoft Knowledge Base Article 240797 (Microsoft)
- NSOADV-2010-006: Authentium Command Free Scan ActiveX Control buffer overflow (NSO Research
)