ICONICS IcoSetServer ActiveX Control Trusted Zone Vulnerability
BID:49406
Info
ICONICS IcoSetServer ActiveX Control Trusted Zone Vulnerability
| Bugtraq ID: | 49406 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 01 2011 12:00AM |
| Updated: | Mar 19 2015 08:52AM |
| Credit: | Billy Rios and Terry McCorkle |
| Vulnerable: |
ICONICS, Inc. GENESIS32 9.21.201.01 ICONICS, Inc. GENESIS32 9.21 ICONICS, Inc. GENESIS32 0 ICONICS, Inc. BizViz 9.21 |
| Not Vulnerable: |
ICONICS, Inc. GENESIS32 9.22 ICONICS, Inc. BizViz 9.22 |
Discussion
ICONICS IcoSetServer ActiveX Control Trusted Zone Vulnerability
ICONICS IcoSetServer ActiveX control is prone to a vulnerability that can allow an attacker to insert an arbitrary domain into the Trusted Zone.
A successful exploit will result in the addition of an arbitrary attacker-supplied domain into the Trusted Zone of the browser. This may potentially allow for the execution of arbitrary code.
ICONICS IcoSetServer ActiveX control is prone to a vulnerability that can allow an attacker to insert an arbitrary domain into the Trusted Zone.
A successful exploit will result in the addition of an arbitrary attacker-supplied domain into the Trusted Zone of the browser. This may potentially allow for the execution of arbitrary code.
Exploit / POC
ICONICS IcoSetServer ActiveX Control Trusted Zone Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to view a maliciously crafted web page.
To exploit this issue, an attacker must entice an unsuspecting user to view a maliciously crafted web page.
Solution / Fix
ICONICS IcoSetServer ActiveX Control Trusted Zone Vulnerability
Solution:
The vendor released an update. Please see the references for details.
Solution:
The vendor released an update. Please see the references for details.
References
ICONICS IcoSetServer ActiveX Control Trusted Zone Vulnerability
References:
References:
- Vendor Homepage (ICONICS, Inc.)
- ICSA-11-182-01�?? ICONICS GENESIS32 AND BIZVIZ ACTIVEX TRUSTED ZONE VULNERABILITY (ICS-CERT)