PT-2008-6099 · Aztec · Azteclib.Mw6Aztec
Deltahackingteam
·
Publicado
2008-11-04
·
Atualizado
2017-09-29
·
CVE-2008-4923
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
AZTECLib.MW6Aztec version 3.0.0.1
Description
The issue concerns insecure methods in the Aztec ActiveX control that allow remote attackers to overwrite arbitrary files. This is achieved by providing a full pathname argument to the
SaveAsBMP and SaveAsWMF methods.Recommendations
For version 3.0.0.1, consider disabling the
SaveAsBMP and SaveAsWMF methods until a patch is available to prevent remote attackers from overwriting arbitrary files. Restrict access to the Aztec.dll module to minimize the risk of exploitation. Avoid using full pathnames as arguments to these methods in the affected API endpoints until the issue is resolved.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Azteclib.Mw6Aztec