Microsoft File Transfer Manager ActiveX Control Buffer Overflow Vulnerability
BID:5508
Info
Microsoft File Transfer Manager ActiveX Control Buffer Overflow Vulnerability
| Bugtraq ID: | 5508 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 19 2002 12:00AM |
| Updated: | Aug 19 2002 12:00AM |
| Credit: | Reported by "Andrew G. Tereschenko" <[email protected]>. |
| Vulnerable: |
Microsoft File Transfer Manager |
| Not Vulnerable: |
Microsoft File Transfer Manager 4.0 |
Discussion
Microsoft File Transfer Manager ActiveX Control Buffer Overflow Vulnerability
The Microsoft File Transfer Manager (FTM) ActiveX control is used to allow beta test customers and others to download files from certain Microsoft sites.
The ActiveX control is reported to contain a buffer overflow that could potentially allow for execution of arbitrary code. Since this ActiveX control is signed by Microsoft, it can be installed without any warnings on a system where the user has chosen to always trust content from Microsoft.
The Microsoft File Transfer Manager (FTM) ActiveX control is used to allow beta test customers and others to download files from certain Microsoft sites.
The ActiveX control is reported to contain a buffer overflow that could potentially allow for execution of arbitrary code. Since this ActiveX control is signed by Microsoft, it can be installed without any warnings on a system where the user has chosen to always trust content from Microsoft.
Exploit / POC
Microsoft File Transfer Manager ActiveX Control Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft File Transfer Manager ActiveX Control Buffer Overflow Vulnerability
Solution:
Reportedly, this issue has been fixed in the newest version of the File Transfer Manager which can be installed from the following website:
http://transfers.one.microsoft.com/ftm/install/HomeIE.asp
Solution:
Reportedly, this issue has been fixed in the newest version of the File Transfer Manager which can be installed from the following website:
http://transfers.one.microsoft.com/ftm/install/HomeIE.asp
References
Microsoft File Transfer Manager ActiveX Control Buffer Overflow Vulnerability
References:
References: