vendor:
EDraw Office Viewer Component
by:
shinnai
7.5
CVSS
HIGH
Unsafe Method Vulnerability
CWE
Product Name: EDraw Office Viewer Component
Affected Version From: 4.0.5.20
Affected Version To: 4.0.5.20
Patch Exists: No
Related CWE:
CPE:
Platforms Tested: Windows XP Professional SP2 with Internet Explorer 7
2007
EDraw Office Viewer Component (edrawofficeviewer.ocx v. 4.0.5.20) Unsafe Method Vulnerability
This exploit targets the EDraw Office Viewer Component (edrawofficeviewer.ocx) version 4.0.5.20. It allows an attacker to delete the system.ini file, potentially causing the PC to not restart. All software that uses this ActiveX component is vulnerable to this exploit. The exploit requires user interaction, as the user needs to click on a button to start the test.
Mitigation:
To mitigate this vulnerability, users should ensure they have a backup of the system.ini file before running the exploit. Additionally, it is recommended to update to a patched version of the EDraw Office Viewer Component.