PT-2007-4236 · Microsoft+1 · Internet Explorer+1

Rgod

·

Published

2007-05-31

·

Updated

2021-07-23

·

CVE-2007-2938

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Ademco ATNBaseLoader100 Module version 5.4.0.6
Description The issue is related to a buffer overflow in the BaseRunner ActiveX control. This can be exploited by remote attackers to execute arbitrary code when using Internet Explorer 6. The exploitation is possible via a long argument to the Send485CMD method. Other potentially vulnerable methods include SetLoginID, AddSite, SetScreen, and SetVideoServer.
Recommendations For Ademco ATNBaseLoader100 Module version 5.4.0.6, consider disabling the Send485CMD method, as well as the SetLoginID, AddSite, SetScreen, and SetVideoServer methods, until a patch is available to prevent potential exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-2938

Affected Products

Ademco Atnbaseloader100 Module
Internet Explorer