Short Name |
HTTP:STC:ACTIVEX:WORD-VIEWER |
---|---|
Severity |
Major |
Recommended |
No |
Recommended Action |
Drop |
Category |
HTTP |
Keywords |
Microsoft Office Word Viewer ActiveX Control |
Release Date |
2014/03/24 |
Update Number |
2356 |
Supported Platforms |
di-5.3+, idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects attempts to use unsafe ActiveX controls in Microsoft Office Word Viewer. An attacker can create a malicious Web site containing Web pages with dangerous ActiveX controls, which if accessed by a victim, allows the attacker to gain control of the victim's client browser.
Word Viewer ActiveX control is prone to multiple denial-of-service and code-execution vulnerabilities. Exploiting these issues allows remote attackers to crash applications that employ the vulnerable controls (typically Microsoft Internet Explorer). Attackers may also execute arbitrary code in the context of an affected user. Word Viewer ActiveX Control 3.2.0.5 is reported vulnerable; other versions may also be affected.