PT-1999-1611 · Hewlett Packard+2 · Hp Pavilion Pc+2
Published
1999-12-31
·
Updated
2016-10-18
·
CVE-1999-1206
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SystemSoft SystemWizard package in HP Pavilion PC with Windows 98
Description
The issue allows remote attackers to execute arbitrary commands via a malicious web page that references either the Launch control or the RegObj control. This is possible because the SystemSoft SystemWizard package installs two ActiveX controls that are marked as safe for scripting.
Recommendations
For SystemSoft SystemWizard package in HP Pavilion PC with Windows 98, consider disabling the Launch and RegObj ActiveX controls as a temporary workaround until a patch is available. Restrict access to these controls to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hp Pavilion Pc
Systemsoft Systemwizard
Windows 98