Microsoft IE5 ActiveX "Eyedog" Vulnerability
BID:619
Info
Microsoft IE5 ActiveX "Eyedog" Vulnerability
| Bugtraq ID: | 619 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Aug 21 1999 12:00AM |
| Updated: | Aug 21 1999 12:00AM |
| Credit: | Reported to Microsoft by Shane Hird, Adrian O'Neill and Richard Smith. |
| Vulnerable: |
Microsoft Internet Explorer 5.0 for Windows NT 4 Microsoft Internet Explorer 5.0 for Windows 98 Microsoft Internet Explorer 5.0 for Windows 95 Microsoft Internet Explorer 5.0 for Windows 2000 Microsoft Internet Explorer 4.0 for Windows NT 4 Microsoft Internet Explorer 4.0 for Windows 95 Microsoft Internet Explorer 4.0 |
| Not Vulnerable: | |
Discussion
Microsoft IE5 ActiveX "Eyedog" Vulnerability
The Eyedog ActiveX control is marked 'safe for scripting' although it permits registry access and other information gathering methods to be used. It also contains a buffer overflow error. These weaknesses can be exploited remotely via a malicious webpage or email.
The Eyedog ActiveX control is marked 'safe for scripting' although it permits registry access and other information gathering methods to be used. It also contains a buffer overflow error. These weaknesses can be exploited remotely via a malicious webpage or email.
Exploit / POC
Microsoft IE5 ActiveX "Eyedog" Vulnerability
This code comes from Shane Hird's <[email protected]> post to Bugtraq.
This code comes from Shane Hird's <[email protected]> post to Bugtraq.
Solution / Fix
Microsoft IE5 ActiveX "Eyedog" Vulnerability
Solution:
Microsoft has released a patch, available at:
Windows 95/98:
ftp://ftp.microsoft.com/peropsys/IE/IE-Public/Fixes/usa/Eyedog-fix/x86/q240308.exe
Windows NT:
ftp://ftp.microsoft.com/peropsys/IE/IE-Public/Fixes/usa/Eyedog-fix/
Solution:
Microsoft has released a patch, available at:
Windows 95/98:
ftp://ftp.microsoft.com/peropsys/IE/IE-Public/Fixes/usa/Eyedog-fix/x86/q240308.exe
Windows NT:
ftp://ftp.microsoft.com/peropsys/IE/IE-Public/Fixes/usa/Eyedog-fix/
References
Microsoft IE5 ActiveX "Eyedog" Vulnerability
References:
References: