Microsoft IE Setupctl ActiveX Control Buffer Overflow Vulnerability
BID:667
Info
Microsoft IE Setupctl ActiveX Control Buffer Overflow Vulnerability
| Bugtraq ID: | 667 |
| Class: | Unknown |
| CVE: | |
| Remote: | Unknown |
| Local: | Yes |
| Published: | Sep 27 1999 12:00AM |
| Updated: | Sep 27 1999 12:00AM |
| Credit: | This vulnerability was identified and posted to the Bugtraq Mailing List by Shane Hird <[email protected]>. |
| Vulnerable: |
Microsoft Internet Explorer 4.0 for Windows NT 4 Microsoft Internet Explorer 4.0 for Windows 95 Microsoft Internet Explorer 4.0 |
| Not Vulnerable: |
Microsoft Internet Explorer 5.0 for Windows NT 4 Microsoft Internet Explorer 5.0 for Windows 98 Microsoft Internet Explorer 5.0 for Windows 95 Microsoft Internet Explorer 5.0 for Windows 2000 |
Discussion
Microsoft IE Setupctl ActiveX Control Buffer Overflow Vulnerability
There is a buffer overflow in the setupctl ActiveX control that used to ship with some versions of Microsoft's Internet Explorer. This ActiveX control is used to link to an update site at Microsoft and is marked 'Safe for Scripting' . Arbitrary commands may be executed if the ActiveX control is run in a malicious manner.
There is a buffer overflow in the setupctl ActiveX control that used to ship with some versions of Microsoft's Internet Explorer. This ActiveX control is used to link to an update site at Microsoft and is marked 'Safe for Scripting' . Arbitrary commands may be executed if the ActiveX control is run in a malicious manner.
Exploit / POC
Microsoft IE Setupctl ActiveX Control Buffer Overflow Vulnerability
This code comes from Shane Hird's <[email protected]> post to Bugtraq.
This code comes from Shane Hird's <[email protected]> post to Bugtraq.
Solution / Fix
Microsoft IE Setupctl ActiveX Control Buffer Overflow Vulnerability
Solution:
Microsoft has released a patch for this vulnerability:
- Internet Explorer 4.01 for Intel:
ftp://ftp.microsoft.com/peropsys/ie/ie-public/fixes/usa/IE401/ImportExportFavorites-fix/x86/q241361.exe
- Internet Explorer 4.01 for Alpha:
ftp://ftp.microsoft.com/peropsys/ie/ie-public/fixes/usa/IE401/ImportExportFavorites-fix/Alpha/q241361.exe
- Internet Explorer 5 for Intel:
ftp://ftp.microsoft.com/peropsys/ie/ie-public/fixes/usa/IE50/ImportExportFavorites-fix/x86/q241361.exe
- Internet Explorer 5 for Alpha:
ftp://ftp.microsoft.com/peropsys/ie/ie-public/fixes/usa/IE50/ImportExportFavorites-fix/Alpha/q241361.exe
Solution:
Microsoft has released a patch for this vulnerability:
- Internet Explorer 4.01 for Intel:
ftp://ftp.microsoft.com/peropsys/ie/ie-public/fixes/usa/IE401/ImportExportFavorites-fix/x86/q241361.exe
- Internet Explorer 4.01 for Alpha:
ftp://ftp.microsoft.com/peropsys/ie/ie-public/fixes/usa/IE401/ImportExportFavorites-fix/Alpha/q241361.exe
- Internet Explorer 5 for Intel:
ftp://ftp.microsoft.com/peropsys/ie/ie-public/fixes/usa/IE50/ImportExportFavorites-fix/x86/q241361.exe
- Internet Explorer 5 for Alpha:
ftp://ftp.microsoft.com/peropsys/ie/ie-public/fixes/usa/IE50/ImportExportFavorites-fix/Alpha/q241361.exe
References
Microsoft IE Setupctl ActiveX Control Buffer Overflow Vulnerability
References:
References: