Soluciones para vulnerabilidades
| La exploración de vulnerabilidades periódica de Nimsoft Cloud Monitor busca la vulnerabilidad siguiente. Para ver las soluciones añadidas más recientemente que Nimsoft Cloud Monitor explora, visite Soluciones para vulnerabilidades. |
| Categoría: Windows | Factor de riesgo: High | Añadido: 13 mar 2010 |
| Synopsis: The remote Windows host has an ActiveX control that is prone to a buffer overflow attack. Description: The CSS Web Installer ActiveX control, a component of the Authentium Command On Demand virus scanner, installed on the remote Windows host reportedly is affected by a buffer overflow involving the 'InstallProduct1' method, and possibly the 'InstallProduct' and 'InstallProduct2' methods as well. If an attacker can trick a user on the affected host into viewing a specially crafted HTML document, he can leverage this issue to execute arbitrary code on the affected system subject to the user's privileges. See also: http://sotiriu.de/adv/NSOADV-2010-006.txt http://archives.neohapsis.com/archives/fulldisclosure/2010-03/0103.html Solution: Remove or disable the control as the product is no longer supported. Risk factor: High / CVSS Base Score : 9.3 (CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C) |
||



