Microsoft TSAC ActiveX Control Cross Site Scripting Vulnerability
BID:5952
Info
Microsoft TSAC ActiveX Control Cross Site Scripting Vulnerability
| Bugtraq ID: | 5952 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 11 2002 12:00AM |
| Updated: | Oct 11 2002 12:00AM |
| Credit: | Discovery credited to ARAI Yuu <[email protected]>. |
| Vulnerable: |
Microsoft TSAC ActiveX Control |
| Not Vulnerable: | |
Discussion
Microsoft TSAC ActiveX Control Cross Site Scripting Vulnerability
Microsoft offers Terminal Services client functionality over the web through the Terminal Services Advanced Client ActiveX control. It is an optional component that is installed by end-users.
An attacker could construct a malicious link to a vulnerable host that contains arbitrary HTML and script code. If this link is visited by a web user, the attacker-supplied code will be rendered in their browser, in the security context of the vulnerable site.
Microsoft offers Terminal Services client functionality over the web through the Terminal Services Advanced Client ActiveX control. It is an optional component that is installed by end-users.
An attacker could construct a malicious link to a vulnerable host that contains arbitrary HTML and script code. If this link is visited by a web user, the attacker-supplied code will be rendered in their browser, in the security context of the vulnerable site.
Exploit / POC
Microsoft TSAC ActiveX Control Cross Site Scripting Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft TSAC ActiveX Control Cross Site Scripting Vulnerability
Solution:
Reportedly, this issue can be fixed by applying the Microsoft patch from security bulletin MS02-046. SecurityFocus has not verified that this is the case.
Microsoft TSAC ActiveX Control
Solution:
Reportedly, this issue can be fixed by applying the Microsoft patch from security bulletin MS02-046. SecurityFocus has not verified that this is the case.
Microsoft TSAC ActiveX Control
-
Microsoft tswebsetup.exe
http://www.microsoft.com/windowsxp/pro/downloads/rdwebconn.asp