Microsoft Silverlight ActiveX Control Pointer Memory Corruption Vulnerability
BID:42138
Info
Microsoft Silverlight ActiveX Control Pointer Memory Corruption Vulnerability
| Bugtraq ID: | 42138 |
| Class: | Unknown |
| CVE: |
CVE-2010-0019 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 10 2010 12:00AM |
| Updated: | Sep 29 2010 09:10PM |
| Credit: | Carsten Book of the Mozilla Corporation |
| Vulnerable: |
Microsoft Silverlight 3.0 |
| Not Vulnerable: | |
Discussion
Microsoft Silverlight ActiveX Control Pointer Memory Corruption Vulnerability
Microsoft Silverlight ActiveX control is prone to a remote memory-corruption vulnerability.
An attacker can exploit this issue by enticing an unsuspecting user to view a malicious webpage.
Successful exploits will allow the attacker to execute arbitrary code within the context of the application (typically Internet Explorer) that uses the ActiveX control.
Microsoft Silverlight ActiveX control is prone to a remote memory-corruption vulnerability.
An attacker can exploit this issue by enticing an unsuspecting user to view a malicious webpage.
Successful exploits will allow the attacker to execute arbitrary code within the context of the application (typically Internet Explorer) that uses the ActiveX control.
Exploit / POC
Microsoft Silverlight ActiveX Control Pointer Memory Corruption Vulnerability
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Microsoft Silverlight ActiveX Control Pointer Memory Corruption Vulnerability
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
Microsoft Silverlight 3.0
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
Microsoft Silverlight 3.0
-
Microsoft Security Update for Microsoft Silverlight (KB978464)
http://www.microsoft.com/downloads/details.aspx?familyid=7e3f6c16-1339 -49bc-a60c-ddc6c3a54850&displaylang=en
References
Microsoft Silverlight ActiveX Control Pointer Memory Corruption Vulnerability
References:
References:
- Microsoft Homepage (Microsoft)
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Microsoft Security Bulletin MS10-060 (Microsoft)