PT-2007-4236 · Microsoft+1 · Internet Explorer+1
Rgod
·
Publicado
2007-05-31
·
Atualizado
2021-07-23
·
CVE-2007-2938
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Ademco ATNBaseLoader100 Module version 5.4.0.6
Description
The issue is related to a buffer overflow in the BaseRunner ActiveX control. This can be exploited by remote attackers to execute arbitrary code when using Internet Explorer 6. The exploitation is possible via a long argument to the
Send485CMD method. Other potentially vulnerable methods include SetLoginID, AddSite, SetScreen, and SetVideoServer.Recommendations
For Ademco ATNBaseLoader100 Module version 5.4.0.6, consider disabling the
Send485CMD method, as well as the SetLoginID, AddSite, SetScreen, and SetVideoServer methods, until a patch is available to prevent potential exploitation.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ademco Atnbaseloader100 Module
Internet Explorer