Short Name |
HTTP:STC:ACTIVEX:MSVIDCTL-2 |
---|---|
Severity |
High |
Recommended |
No |
Recommended Action |
Drop |
Category |
HTTP |
Keywords |
Unsafe Microsoft Video ActiveX Control (2) |
Release Date |
2009/07/14 |
Update Number |
1461 |
Supported Platforms |
idp-4.0.110090709+, isg-3.1.134269+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to use unsafe ActiveX components in Microsoft Windows system. An attacker can create a malicious Web site containing Web pages with dangerous ActiveX components, which if accessed by a victim, allows the attacker to gain control of the victim's client browser.
The Microsoft Active Template Library (ATL) is prone to a remote code-execution vulnerability. This issue affects a private version of the ATL used internally by Microsoft; components written by other vendors are likely unaffected. Remote attackers can exploit this issue to execute arbitrary code with the privileges of the user running an application built against the affected library. Failed exploit attempts will result in a denial-of-service condition. NOTE: This BID was previously titled "Microsoft Windows 'MPEG2TuneRequest' ActiveX Control Remote Code Execution Vulnerability". It has been updated to better reflect the issue.