Short Name |
SMB:OLEAUT32-WMF |
---|---|
Severity |
High |
Recommended |
No |
Recommended Action |
Drop |
Category |
SMB |
Keywords |
Microsoft Windows 'OLEAUT32.DLL' OLE Automation WMF Remote Code Execution |
Release Date |
2011/06/13 |
Update Number |
1937 |
Supported Platforms |
idp-4.1.110110609+, isg-3.4.139899+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to exploit a known vulnerability against Microsoft Windows OLE Automation. A successful attack can lead to arbitrary code execution.
Microsoft Object Linking and Embedding (OLE) Automation is prone to a remote code-execution vulnerability because of an underflow error. An attacker can exploit this issue by enticing an unsuspecting user to view a malicious webpage or a specially crafted file. Successful exploits will allow the attacker to execute arbitrary code in the context of the user running the application, which can compromise the application and possibly the computer.