Microsoft MCIWNDX.OCX ActiveX Control Buffer Overflow Vulnerability
BID:8413
Info
Microsoft MCIWNDX.OCX ActiveX Control Buffer Overflow Vulnerability
| Bugtraq ID: | 8413 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 13 2003 12:00AM |
| Updated: | Aug 13 2003 12:00AM |
| Credit: | Discovery is credited to Tri Huynh <[email protected]>. |
| Vulnerable: |
Microsoft Visual Studio 6.0 |
| Not Vulnerable: | |
Discussion
Microsoft MCIWNDX.OCX ActiveX Control Buffer Overflow Vulnerability
The ActiveX control 'mciwndx.ocx' has been reported prone to a buffer overflow vulnerability. The issue reportedly presents itself when excessive data is passed to an internal function.
This issue could potentially lead to the execution of code with the privileges of the user executing the web browser. This problem requires that a user with the vulnerable control installed visit a web page that invokes the control in a manner sufficient to trigger the issue.
The ActiveX control 'mciwndx.ocx' has been reported prone to a buffer overflow vulnerability. The issue reportedly presents itself when excessive data is passed to an internal function.
This issue could potentially lead to the execution of code with the privileges of the user executing the web browser. This problem requires that a user with the vulnerable control installed visit a web page that invokes the control in a manner sufficient to trigger the issue.
Exploit / POC
Microsoft MCIWNDX.OCX ActiveX Control Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft MCIWNDX.OCX ActiveX Control Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft MCIWNDX.OCX ActiveX Control Buffer Overflow Vulnerability
References:
References:
- Technet Security (Microsoft)
- Microsoft MCWNDX.OCX ActiveX buffer overflow ("Tri Huynh"
)