|
|
Family: Windows --> Category: infos
WinZip FileView ActiveX Control Vulnerabilities Vulnerability Scan
Vulnerability Scan Summary Checks version of FileView ActiveX control
Detailed Explanation for this Vulnerability Test
Synopsis :
The remote Windows host has an ActiveX control that is affected by an
arbitrary code execution and buffer overflow vulnerabilities.
Description :
The remote host contains a version of the 'FileView' ActiveX control
from Sky Software and included in third-party products such as WinZip.
The version of this ActiveX control on the remote host reportedly
exposes several methods that either can be used to execute arbitrary
code or are affected by buffer overflow vulnerabilities. If an
attacker can trick a user on the affected host into visiting a
specially-crafted web page, he can leverage these issues to execute
arbitrary code on the host subject to the user's rights.
See also :
http://www.zerodayinitiative.com/advisories/ZDI-06-040.html
http://archives.neohapsis.com/archives/fulldisclosure/2006-11/0247.html
http://www.kb.cert.org/vuls/id/225217
http://www.winzip.com/wz7245.htm
Solution :
Upgrade to version 6.1.7242.0 or later of the control or WinZip 10
build 7245 or later.
Threat Level:
High / CVSS Base Score : 7.0
(AV:R/AC:L/Au:NR/C:P/I:P/A:P/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|