vendor:
DRM Technology
by:
Asheesh Kumar Mani Tripathi
9,3
CVSS
HIGH
Buffer Overflow, Integer Overflow, Denial of Service
119
CWE
Product Name: DRM Technology
Affected Version From: Microsoft DRM technology (msnetobj.dll) ActiveX
Affected Version To: Microsoft DRM technology (msnetobj.dll) ActiveX
Patch Exists: YES
Related CWE: CVE-2010-3297
CPE: o:microsoft:drm_technology
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2010
Microsoft DRM technology (msnetobj.dll) ActiveX Multiple Remote Vulnerabilities
Microsoft DRM technology (msnetobj.dll) ActiveX suffers from multiple remote vulnerabilities such as buffer overflow, integer overflow and denial of service (IE crash). This issue is triggered when an attacker convinces a victim user to visit a malicious website. The "GetLicenseFromURLAsync" function does not handle input correctly. Remote attackers may exploit this issue to execute arbitrary machine code in the context of the affected application, facilitating the remote compromise of affected computers. Failed exploit attempts likely result in browser crashes.
Mitigation:
Upgrade to the latest version of Microsoft DRM technology (msnetobj.dll) ActiveX.