Microsoft MSN Setup BBS ActiveX Control Buffer Overflow Vulnerability
BID:668
Info
Microsoft MSN Setup BBS ActiveX Control Buffer Overflow Vulnerability
| Bugtraq ID: | 668 |
| Class: | Unknown |
| CVE: |
CVE-1999-1484 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 27 1999 12:00AM |
| Updated: | Jul 11 2009 12:56AM |
| Credit: | This vulnerability was identified and posted to the Bugtraq Mailing List by Shane Hird <[email protected]>. |
| Vulnerable: |
Microsoft MSN Messenger Service 1.0 |
| Not Vulnerable: | |
Discussion
Microsoft MSN Setup BBS ActiveX Control Buffer Overflow Vulnerability
There is a buffer overflow in the 4.71.0.10 version of the MSN Setup BBS ActiveX control (setupbbs.ocx).. This ActiveX control is marked 'Safe for Scripting' . Arbitrary commands may be executed if the ActiveX control is run in a malicious manner.
There is a buffer overflow in the 4.71.0.10 version of the MSN Setup BBS ActiveX control (setupbbs.ocx).. This ActiveX control is marked 'Safe for Scripting' . Arbitrary commands may be executed if the ActiveX control is run in a malicious manner.
Exploit / POC
Microsoft MSN Setup BBS ActiveX Control Buffer Overflow Vulnerability
This code comes from Shane Hird's <[email protected]> post to Bugtraq.
This code comes from Shane Hird's <[email protected]> post to Bugtraq.
References
Microsoft MSN Setup BBS ActiveX Control Buffer Overflow Vulnerability
References:
References: