Microsoft Windows Object Linking and Embedding (OLE) Automation Remote Code Execution Vulnerability
BID:57863
Info
Microsoft Windows Object Linking and Embedding (OLE) Automation Remote Code Execution Vulnerability
| Bugtraq ID: | 57863 |
| Class: | Unknown |
| CVE: |
CVE-2013-1313 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 12 2013 12:00AM |
| Updated: | May 21 2013 08:13AM |
| Credit: | Nicolas Joly of VUPEN Security working with TippingPoint's Zero Day Initiative |
| Vulnerable: |
Microsoft Windows XP Service Pack 3 0 Microsoft Internet Explorer 9 Avaya Messaging Application Server 0 Avaya Meeting Exchange - Web Conferencing Server 0 Avaya Meeting Exchange - Streaming Server 0 Avaya Meeting Exchange - Recording Server 0 Avaya Meeting Exchange - Client Registration Server 0 Avaya Communication Server 1000 Telephony Manager 0 Avaya CallPilot 0 Avaya Aura Conferencing Standard |
| Not Vulnerable: | |
Discussion
Microsoft Windows Object Linking and Embedding (OLE) Automation Remote Code Execution Vulnerability
Microsoft Windows Object Linking and Embedding (OLE) Automation is prone to a remote code-execution vulnerability due to an integer overflow error.
An attacker can exploit this issue by enticing an unsuspecting user to view a malicious webpage or a specially crafted file.
Successful exploits will allow the attacker to execute arbitrary code in the context of the user running the application, which can compromise the application, and possibly, the computer.
Microsoft Windows Object Linking and Embedding (OLE) Automation is prone to a remote code-execution vulnerability due to an integer overflow error.
An attacker can exploit this issue by enticing an unsuspecting user to view a malicious webpage or a specially crafted file.
Successful exploits will allow the attacker to execute arbitrary code in the context of the user running the application, which can compromise the application, and possibly, the computer.
Exploit / POC
Microsoft Windows Object Linking and Embedding (OLE) Automation Remote Code Execution Vulnerability
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Microsoft Windows Object Linking and Embedding (OLE) Automation Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.