AOL Deskbar Uninitialized Pointer Remote Code Execution Vulnerability
BID:54146
Info
AOL Deskbar Uninitialized Pointer Remote Code Execution Vulnerability
| Bugtraq ID: | 54146 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 22 2012 12:00AM |
| Updated: | Jun 22 2012 12:00AM |
| Credit: | Andrea Micalizzi aka rgod |
| Vulnerable: |
AOL Deskbar 0 |
| Not Vulnerable: | |
Discussion
AOL Deskbar Uninitialized Pointer Remote Code Execution Vulnerability
AOL Deskbar is prone to a remote code-execution vulnerability.
Attackers can exploit this issue by enticing an unsuspecting user to open a specially crafted page or file.
Successful exploit attempts allow an attacker to execute arbitrary code within the context of the application that uses the ActiveX control. Failed exploit attempts will result in a denial-of-service condition.
AOL Deskbar is prone to a remote code-execution vulnerability.
Attackers can exploit this issue by enticing an unsuspecting user to open a specially crafted page or file.
Successful exploit attempts allow an attacker to execute arbitrary code within the context of the application that uses the ActiveX control. Failed exploit attempts will result in a denial-of-service condition.
Solution / Fix
AOL Deskbar Uninitialized Pointer Remote Code Execution Vulnerability
Solution:
Vendor updates are available. Please see the references for details.
Solution:
Vendor updates are available. Please see the references for details.
References
AOL Deskbar Uninitialized Pointer Remote Code Execution Vulnerability
References:
References:
- AOL Deskbar Homepage (AOL)
- AOL Homepage (AOL)
- AOL dnUpdater Uninitialized Pointer Remote Code Execution Vulnerability : ZDI-12 (Zero Day Initiative)