vendor:
ProgramChecker ActiveX Control
by:
shinnai
7.5
CVSS
HIGH
Insecure Method
CWE
Product Name: ProgramChecker ActiveX Control
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP Professional SP2 with Internet Explorer 7
2007
Zenturi ProgramChecker ActiveX Control “NavigateUrl()” Insecure Method
The Zenturi ProgramChecker ActiveX Control "NavigateUrl()" method allows arbitrary local file execution on a target system. This can be exploited to download and execute malicious files on a victim's machine. The vulnerability was discovered by shinnai and reported on milw0rm.com.
Mitigation:
Apply the latest patches and updates for the Zenturi ProgramChecker ActiveX Control. Disable or remove the control if it is not necessary.