PT-2007-4236 · Microsoft+1 · Internet Explorer+1

Rgod

·

Publicado

2007-05-31

·

Atualizado

2021-07-23

·

CVE-2007-2938

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Ademco ATNBaseLoader100 Module version 5.4.0.6
Description The issue is related to a buffer overflow in the BaseRunner ActiveX control. This can be exploited by remote attackers to execute arbitrary code when using Internet Explorer 6. The exploitation is possible via a long argument to the Send485CMD method. Other potentially vulnerable methods include SetLoginID, AddSite, SetScreen, and SetVideoServer.
Recommendations For Ademco ATNBaseLoader100 Module version 5.4.0.6, consider disabling the Send485CMD method, as well as the SetLoginID, AddSite, SetScreen, and SetVideoServer methods, until a patch is available to prevent potential exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-2938

Produtos afetados

Ademco Atnbaseloader100 Module
Internet Explorer