This site is deprecated. Please
CLICK HERE for latest updates
Short Name |
HTTP:STC:ACTIVEX:VS05-INJ
|
Severity |
Major
|
Recommended |
No
|
Recommended Action |
Drop
|
Category |
HTTP
|
Keywords |
Visual Studio Unsafe ActiveX Control Remote Control Execution
|
Release Date |
2006/12/12
|
Update Number |
1213
|
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+
|
HTTP: Visual Studio Unsafe ActiveX Control Remote Control Execution
This signature detects attempts to use unsafe ActiveX controls in Visual Studio. An attacker can create a malicious Web site containing Web pages with dangerous ActiveX controls, which if accessed by a victim, allows the attacker to gain control of the victim's client application.
Extended Description
Microsoft Visual Studio 2005 is prone to a vulnerability that could allow remote attackers to execute arbitrary code. This issue occurs because of an unspecified error in the WMI Object Broker ActiveX Control.
The vulnerability is triggered when a user visits a malicious website using Internet Explorer. Since arbitrary code execution is possible, a successful exploit could facilitate a complete compromise of the affected system.
Microsoft Visual Studio 2005 is reported affected. Implementations of Visual Studio 2005 on Windows Server 2003 and Windows Server 2003 Service Pack 1 with Enhanced Security activated are not vulnerable. Nor are Visual Studio 2005 users who are running Internet Explorer 7 with default security settings.
Affected Products
- Avaya agent_access
- Avaya basic_call_management_system_reporting_desktop server
- Avaya basic_call_management_system_reporting_desktop
- Avaya cms_supervisor
- Avaya computer_telephony
- Avaya contact_center_express
- Avaya cvlan
- Avaya enterprise_management
- Avaya integrated_management 2.1.0
- Avaya integrated_management
- Avaya interaction_center
- Avaya interaction_center-voice_quick_start
- Avaya ip_agent
- Avaya ip_softphone
- Avaya modular_messaging S3400
- Avaya modular_messaging_(mas) 3.0.0
- Avaya modular_messaging_(mas)
- Avaya modular_messaging_(mss) 1.1.0
- Avaya modular_messaging_(mss) 2.0.0
- Avaya modular_messaging_(mss) 2.0.0 SP4
- Avaya network_reporting
- Avaya octelaccess(r)_server
- Avaya octeldesignertm
- Avaya operational_analyst
- Avaya outbound_contact_management
- Avaya speech_access
- Avaya unified_communication_center
- Avaya unified_communications_center_s3400
- Avaya unified_messenger_(r)
- Avaya visual_messenger_tm
- Avaya visual_vector_client
- Avaya vpnmanagertm_console
- Avaya web_messenger
- Microsoft visual_studio_2005
- Microsoft visual_studio_2005_professional_edition
- Microsoft visual_studio_2005_standard_edition
- Microsoft visual_studio_2005_team_edition
- Microsoft visual_studio_2005_team_edition_for_architects
- Microsoft visual_studio_2005_team_edition_for_developers
- Microsoft visual_studio_2005_team_edition_for_testers
References