Title: Microsoft Agent URL Handling Remote Code Execution
Info
Disclosure
Sep 11, 2007
Discovery
Unknown
Dates
Exploit
Unknown
Solution
Unknown
Description
A remote overflow exists in Microsoft Windows 2000 Agent ActiveX control. The ActiveX control fails to sanitize URLs passed as argument to a certain unspecified method, resulting in a stack-based buffer overflow. With a specially crafted request, an attacker can cause execution of arbitrary code resulting in a loss of confidentiality, integrity, and/or availability.