OSVDB ID: 20887

Title: Sony CD First4Internet XCP Uninstallation CodeSupport.ocx ActiveX Control Arbitrary Code Execution

Info

Disclosure

Nov 15, 2005

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

Unknown or Incomplete

Classification

Location: Remote / Network Access, Context Dependent
Attack Type: Input Manipulation
Impact: Loss of Integrity

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, Microsoft has released a patch to address this vulnerability. The MS05-054 cumulative update sets the kill bit on the First4Internet XCP Uninstallation ActiveX control.

Products

Unknown or Incomplete

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/20887