PT-2004-3553 · Ibm · Ibm Access Support Egatherer Activex Control

Drew Copley

·

Published

2004-12-31

·

Updated

2017-07-20

·

CVE-2004-2663

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions IBM Access Support eGatherer ActiveX control version 2.0.0.16
Description The issue allows remote attackers to create files with arbitrary content. This is demonstrated by creating a .hta file in a Startup folder, utilizing the SetDebugging and RunEgatherer methods in the IBM Access Support eGatherer ActiveX control.
Recommendations For version 2.0.0.16, consider disabling the SetDebugging and RunEgatherer methods as a temporary workaround until a patch is available. Restrict access to the ActiveX control to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-2663

Affected Products

Ibm Access Support Egatherer Activex Control