Soluções para vulnerabilidades

O Exame Periódico de Vulnerabilidade do Nimsoft Cloud Monitor verifica a vulnerabilidade abaixo. Para ver as soluções para vulneralidades adicionadas mais recentemente que são examinadas pelo WatchMouse, acesse a visão geral das Soluções para vulnerabilidades

Categoria: Windows Fator de risco: High Adicionado: 13 Mar 2010
Synopsis:

The remote Windows host has an ActiveX control that is prone to a buffer overflow attack.

Description:

The CSS Web Installer ActiveX control, a component of the Authentium Command On Demand virus scanner, installed on the remote Windows host reportedly is affected by a buffer overflow involving the 'InstallProduct1' method, and possibly the 'InstallProduct' and 'InstallProduct2' methods as well.

If an attacker can trick a user on the affected host into viewing a specially crafted HTML document, he can leverage this issue to execute arbitrary code on the affected system subject to the user's
privileges.

See also:

http://sotiriu.de/adv/NSOADV-2010-006.txt
http://archives.neohapsis.com/archives/fulldisclosure/2010-03/0103.html

Solution:

Remove or disable the control as the product is no longer supported.

Risk factor:

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)