PT-2007-4236 · Microsoft+1 · Internet Explorer+1
Rgod
·
Published
2007-05-31
·
Updated
2021-07-23
·
CVE-2007-2938
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Ademco ATNBaseLoader100 Module version 5.4.0.6
Description
The issue is related to a buffer overflow in the BaseRunner ActiveX control. This can be exploited by remote attackers to execute arbitrary code when using Internet Explorer 6. The exploitation is possible via a long argument to the
Send485CMD method. Other potentially vulnerable methods include SetLoginID, AddSite, SetScreen, and SetVideoServer.Recommendations
For Ademco ATNBaseLoader100 Module version 5.4.0.6, consider disabling the
Send485CMD method, as well as the SetLoginID, AddSite, SetScreen, and SetVideoServer methods, until a patch is available to prevent potential exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ademco Atnbaseloader100 Module
Internet Explorer