Microsoft Indexing Service 'ixsso.dll' ActiveX Control Denial of Service Vulnerability
BID:55202
Info
Microsoft Indexing Service 'ixsso.dll' ActiveX Control Denial of Service Vulnerability
| Bugtraq ID: | 55202 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 24 2012 12:00AM |
| Updated: | Aug 24 2012 12:00AM |
| Credit: | coolkaveh |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Microsoft Indexing Service 'ixsso.dll' ActiveX Control Denial of Service Vulnerability
Microsoft Indexing Service 'ixsso.dll' ActiveX control is prone to a denial-of-service vulnerability due to a null-pointer dereference error.
An attacker may exploit this issue by enticing victims into opening a malicious webpage or HTML email that invokes the affected control.
The attacker can exploit this issue to cause denial-of-service conditions in Internet Explorer or other applications that use the vulnerable ActiveX control. Due to the nature of this issue, arbitrary code execution may be possible, but this has not been confirmed.
Microsoft Indexing Service 'ixsso.dll' ActiveX control is prone to a denial-of-service vulnerability due to a null-pointer dereference error.
An attacker may exploit this issue by enticing victims into opening a malicious webpage or HTML email that invokes the affected control.
The attacker can exploit this issue to cause denial-of-service conditions in Internet Explorer or other applications that use the vulnerable ActiveX control. Due to the nature of this issue, arbitrary code execution may be possible, but this has not been confirmed.
Exploit / POC
Microsoft Indexing Service 'ixsso.dll' ActiveX Control Denial of Service Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
Microsoft Indexing Service 'ixsso.dll' ActiveX Control Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Microsoft Indexing Service 'ixsso.dll' ActiveX Control Denial of Service Vulnerability
References:
References:
- Microsoft Homepage (Microsoft)
- Microsoft Knowledge Base Article 240797 (Microsoft)