AVG Secure Search 'ScriptHelperApi' ActiveX Control Remote Code Execution Vulnerability
BID:68421
Info
AVG Secure Search 'ScriptHelperApi' ActiveX Control Remote Code Execution Vulnerability
| Bugtraq ID: | 68421 |
| Class: | Unknown |
| CVE: |
CVE-2014-2956 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 07 2014 12:00AM |
| Updated: | Jul 07 2014 12:00AM |
| Credit: | Will Dormann of the CERT/CC |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
AVG Secure Search 'ScriptHelperApi' ActiveX Control Remote Code Execution Vulnerability
AVG Secure Search is prone to a remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code in the context of an application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
AVG Secure Search is prone to a remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code in the context of an application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
Exploit / POC
AVG Secure Search 'ScriptHelperApi' ActiveX Control Remote Code Execution Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into viewing a malicious webpage.
To exploit this issue, an attacker must entice an unsuspecting victim into viewing a malicious webpage.
Solution / Fix
AVG Secure Search 'ScriptHelperApi' ActiveX Control Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
AVG Secure Search 'ScriptHelperApi' ActiveX Control Remote Code Execution Vulnerability
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)