Solutions de vulnérabilité

L'analyse périodique de vulnérabilité Nimsoft Cloud Monitor vérifie la vulnérabilité ci-dessous. Pour connaître les solutions de vulnérabilité les plus récemment ajoutées analysées par WatchMouse, rendez-vous sur la vue d'ensemble Solutions de vulnérabilité

Catégorie: Windows Facteur de risque: High Ajouté: 13 mars 2010
Synopsis:

The remote Windows host has an ActiveX control that is prone to a buffer overflow attack.

Description:

The CSS Web Installer ActiveX control, a component of the Authentium Command On Demand virus scanner, installed on the remote Windows host reportedly is affected by a buffer overflow involving the 'InstallProduct1' method, and possibly the 'InstallProduct' and 'InstallProduct2' methods as well.

If an attacker can trick a user on the affected host into viewing a specially crafted HTML document, he can leverage this issue to execute arbitrary code on the affected system subject to the user's
privileges.

See also:

http://sotiriu.de/adv/NSOADV-2010-006.txt
http://archives.neohapsis.com/archives/fulldisclosure/2010-03/0103.html

Solution:

Remove or disable the control as the product is no longer supported.

Risk factor:

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)