vendor:
AnswerWorks 4 API
by:
Parvez Anwar
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: AnswerWorks 4 API
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2007-6387
CPE: a:vantage_linguistics:answerworks_api:4.0.0.44
Platforms Tested: Windows XP SP2 with IE6
2007
Vantage Linguistics AnswerWorks 4 API ActiveX Control Buffer Overflow Exploit
This exploit takes advantage of a buffer overflow vulnerability in the Vantage Linguistics AnswerWorks 4 API ActiveX Control. It allows an attacker to execute arbitrary code on a vulnerable system.
Mitigation:
Apply the patches provided by Microsoft in MS07-069/942615. Additionally, consider disabling the vulnerable ActiveX control.