Computer Associates WebScan ActiveX Control Multiple Remote Code Execution Vulnerabilities
BID:40689
Info
Computer Associates WebScan ActiveX Control Multiple Remote Code Execution Vulnerabilities
| Bugtraq ID: | 40689 |
| Class: | Unknown |
| CVE: |
CVE-2010-2193 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 09 2010 12:00AM |
| Updated: | Apr 12 2011 05:35PM |
| Credit: | Elazar Broad of Trancek |
| Vulnerable: |
Computer Associates WebScan 0 |
| Not Vulnerable: | |
Discussion
Computer Associates WebScan ActiveX Control Multiple Remote Code Execution Vulnerabilities
Computer Associates WebScan ActiveX control is prone to multiple remote code-execution vulnerabilities.
Attackers may exploit these issues by enticing an unsuspecting victim to view a malicious webpage.
Successfully exploiting these issues will allow attackers to execute arbitrary code within the context of the application that uses the ActiveX control (typically Internet Explorer).
Computer Associates WebScan ActiveX control is prone to multiple remote code-execution vulnerabilities.
Attackers may exploit these issues by enticing an unsuspecting victim to view a malicious webpage.
Successfully exploiting these issues will allow attackers to execute arbitrary code within the context of the application that uses the ActiveX control (typically Internet Explorer).
Exploit / POC
Computer Associates WebScan ActiveX Control Multiple Remote Code Execution Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Computer Associates WebScan ActiveX Control Multiple Remote Code Execution Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of mo recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of mo recent information, please mail us at: [email protected].
References
Computer Associates WebScan ActiveX Control Multiple Remote Code Execution Vulnerabilities
References:
References:
- CA20100608-01: Security Notice for CA PSFormX and WebScan ActiveX Controls (Computer Associates)
- Computer Associates Homepage (Computer Associates)
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Microsoft Security Bulletin MS11-027 (Microsoft)