PT-2004-3553 · Ibm · Ibm Access Support Egatherer Activex Control

Drew Copley

·

Publicado

2004-12-31

·

Atualizado

2017-07-20

·

CVE-2004-2663

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions IBM Access Support eGatherer ActiveX control version 2.0.0.16
Description The issue allows remote attackers to create files with arbitrary content. This is demonstrated by creating a .hta file in a Startup folder, utilizing the SetDebugging and RunEgatherer methods in the IBM Access Support eGatherer ActiveX control.
Recommendations For version 2.0.0.16, consider disabling the SetDebugging and RunEgatherer methods as a temporary workaround until a patch is available. Restrict access to the ActiveX control to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-2663

Produtos afetados

Ibm Access Support Egatherer Activex Control