Ubisoft CoGSManager ActiveX Control 'Initialize()' Method Stack Buffer Overflow Vulnerability
BID:48462
Info
Ubisoft CoGSManager ActiveX Control 'Initialize()' Method Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 48462 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 27 2011 12:00AM |
| Updated: | Mar 19 2015 08:41AM |
| Credit: | Luigi Auriemma |
| Vulnerable: |
Ubisoft Entertainment CoGSManager ActiveX Control 1.0.0.23 |
| Not Vulnerable: | |
Discussion
Ubisoft CoGSManager ActiveX Control 'Initialize()' Method Stack Buffer Overflow Vulnerability
The Ubisoft CoGSManager ActiveX control is prone to a remote stack-based buffer-overflow vulnerability because the application fails to properly bounds check user-supplied input.
Attackers can exploit this issue to execute arbitrary code within the context of an application (typically Internet Explorer) that uses the ActiveX control. Failed exploit attempts will result in a denial-of-service condition.
Ubisoft CoGSManager ActiveX control 1.0.0.23 is vulnerable.
The Ubisoft CoGSManager ActiveX control is prone to a remote stack-based buffer-overflow vulnerability because the application fails to properly bounds check user-supplied input.
Attackers can exploit this issue to execute arbitrary code within the context of an application (typically Internet Explorer) that uses the ActiveX control. Failed exploit attempts will result in a denial-of-service condition.
Ubisoft CoGSManager ActiveX control 1.0.0.23 is vulnerable.
Exploit / POC
Ubisoft CoGSManager ActiveX Control 'Initialize()' Method Stack Buffer Overflow Vulnerability
The following proof of concept code is available:
The following proof of concept code is available:
Solution / Fix
Ubisoft CoGSManager ActiveX Control 'Initialize()' Method Stack Buffer Overflow Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Ubisoft CoGSManager ActiveX Control 'Initialize()' Method Stack Buffer Overflow Vulnerability
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Ubisoft Gaming Zone (Ubisoft Entertainment)
- Ubisoft Gaming Zone (aka GS4) ActiveX Buffer Overflow (Luigi Auriemma)