Short Name |
HTTP:STC:ACTIVEX:ARGOSOFT-MAIL |
---|---|
Severity |
High |
Recommended |
No |
Recommended Action |
Drop |
Category |
HTTP |
Keywords |
ArGoSoft Mail Server MLSRVX.DLL Unsafe ActiveX Control |
Release Date |
2012/11/07 |
Update Number |
2201 |
Supported Platforms |
di-5.3+, idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to use unsafe ActiveX control in ArGoSoft Mail Server. An attacker can create a malicious Web site containing Web pages with dangerous ActiveX controls, which if accessed by a victim, allows the attacker to gain control of the victim's client browser.
ArGoSoft Mail Server is prone to a vulnerability that lets attackers overwrite arbitrary files. An attacker can exploit this issue to overwrite arbitrary files on the victim's computer in the context of the vulnerable application using the ActiveX control (typically Internet Explorer). Successful exploits will allow the attacker to cause denial-of-service conditions; other consequences are possible. ArGoSoft Mail Server 1.8.9.1 is vulnerable; other versions may also be affected.