Microsoft IE5 ActiveX "Object for constructing type libraries for scriptlets" Vulnerability
BID:598
Info
Microsoft IE5 ActiveX "Object for constructing type libraries for scriptlets" Vulnerability
| Bugtraq ID: | 598 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-1999-0668 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 21 1999 12:00AM |
| Updated: | Jul 16 2007 10:06PM |
| Credit: | Posted to Bugtraq by Georgi Guninski <[email protected]> on August 21, 1999. |
| Vulnerable: |
Microsoft Internet Explorer 5.0 for Windows NT 4 Microsoft Internet Explorer 5.0 for Windows 98 Microsoft Internet Explorer 5.0 for Windows 95 |
| Not Vulnerable: | |
Discussion
Microsoft IE5 ActiveX "Object for constructing type libraries for scriptlets" Vulnerability
The 'scriptlet.typlib' ActiveX control can create, edit, and overwrite files on the local disk. This means that an executable text file (e.g. a '.hta' file) can be written to the startup folder of a remote machine and will be executed the next time that machine reboots. Attackers can exploit this vulnerability via a malicious web page or an email message.
The 'scriptlet.typlib' ActiveX control can create, edit, and overwrite files on the local disk. This means that an executable text file (e.g. a '.hta' file) can be written to the startup folder of a remote machine and will be executed the next time that machine reboots. Attackers can exploit this vulnerability via a malicious web page or an email message.
Solution / Fix
Microsoft IE5 ActiveX "Object for constructing type libraries for scriptlets" Vulnerability
Solution:
Microsoft has released a patch:
Windows 95/98:
ftp://ftp.microsoft.com/peropsys/IE/IE-Public/Fixes/usa/Eyedog-fix/x86/q240308.exe
Windows NT:
ftp://ftp.microsoft.com/peropsys/IE/IE-Public/Fixes/usa/Eyedog-fix/
Solution:
Microsoft has released a patch:
Windows 95/98:
ftp://ftp.microsoft.com/peropsys/IE/IE-Public/Fixes/usa/Eyedog-fix/x86/q240308.exe
Windows NT:
ftp://ftp.microsoft.com/peropsys/IE/IE-Public/Fixes/usa/Eyedog-fix/
References
Microsoft IE5 ActiveX "Object for constructing type libraries for scriptlets" Vulnerability
References:
References: