Short Name |
HTTP:STC:CLSID:ACTIVEX:MACRO-AX |
---|---|
Severity |
Medium |
Recommended |
No |
Recommended Action |
Drop |
Category |
HTTP |
Keywords |
Macrovision FLEXnet boisweb.dll ActiveX Control Buffer Overflow Vulnerability |
Release Date |
2007/06/08 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to exploit a known vulnerability against Macrovision FLEXnet. An attacker can create a malicious Web site containing dangerous Active X calls, which if accessed by a victim, can allow the attacker to gain control of the victim's client browser.
Macrovision FLEXNet ActiveX Control is prone to a buffer-overflow vulnerability. Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.