PT-2007-6005 · Microsoft · Visual Studio
Shinnai
·
Publicado
2007-09-14
·
Atualizado
2017-09-29
·
CVE-2007-4891
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Microsoft Visual Studio 6.0 versions 6.0.0.9782 and earlier
Description:
The issue concerns a certain ActiveX control in PDWizard.ocx that exposes several dangerous methods, including
StartProcess, SyncShell, SaveAs, CABDefaultURL, CABFileName, and CABRunFile. This exposure allows remote attackers to execute arbitrary programs and have other impacts. For example, using absolute pathnames in arguments to StartProcess and SyncShell can demonstrate this vulnerability.Recommendations:
For Microsoft Visual Studio 6.0 versions 6.0.0.9782 and earlier, consider disabling the
StartProcess and SyncShell methods as a temporary workaround to minimize the risk of exploitation. Additionally, restrict access to the SaveAs, CABDefaultURL, CABFileName, and CABRunFile methods until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
OS Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Visual Studio