Vulnerability Scanning Solutions, LLC.
Home
Our Process
Residential
Corporate
What We Scan For
Sample Report
Client List
Terms
Contact Us
What We Scan For
Family: Windows --> Category: infos

CA eTrust Antivirus WebScan ActiveX Control Vulnerabilities Vulnerability Scan


Vulnerability Scan Summary
Checks for version of WebScan ActiveX control

Detailed Explanation for this Vulnerability Test

Synopsis :

The remote Windows host has an ActiveX control that is affected by
multiple vulnerabilities.

Description :

The Windows remote host contains the WebScan ActiveX control, which is
used by Computer Associates' eTrust Antivirus WebScan service.

The version of this ActiveX control on the remote host reportedly
contains a buffer overflow and fails to properly validate parameters.
Exploitation of these issues may allow an unauthenticated remote
attacker to execute arbitrary code or gain privileged access.

See also :

http://www.securityfocus.com/archive/1/442476/30/0/threaded
http://www.tippingpoint.com/security/advisories/TSRT-06-05.html
http://archives.neohapsis.com/archives/fulldisclosure/2006-08/0126.html
http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=34509

Solution :

Either remote the control or upgrade to WebScan v1.1.0.1048 or later
by visiting http://www3.ca.com/securityadvisor/virusinfo/scan.aspx and
allowing Internet Explorer to update a new version of webscan.cab.

Threat Level:

High / CVSS Base Score : 7.0
(AV:R/AC:L/Au:NR/C:P/I:P/A:P/B:N)

Click HERE for more information and discussions on this network vulnerability scan.

VSS, LLC.

P.O. Box 827051

Pembroke Pines, FL 33082-7051

Vulnerability Scanning Solutions, LLC.