vendor:
PrivAgent ActiveX Control
by:
Blake
9,3
CVSS
HIGH
ActiveX Control Overflow
119
CWE
Product Name: PrivAgent ActiveX Control
Affected Version From: activex2002
Affected Version To: activex2002
Patch Exists: YES
Related CWE: CVE-2008-4609
CPE: a:aladdin_knowledge_systems:privagent_activex_control
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 2003 SP2 / IE 7
2008
Aladdin Knowledge Systems Ltd. PrivAgent ActiveX Control Overflow
A buffer overflow vulnerability exists in Aladdin Knowledge Systems Ltd. PrivAgent ActiveX Control due to improper bounds checking of user-supplied input. An attacker can exploit this vulnerability by enticing a victim to visit a malicious web page containing a specially crafted HTML that when loaded, will trigger the overflow and execute arbitrary code on the victim's system.
Mitigation:
Upgrade to the latest version of Aladdin Knowledge Systems Ltd. PrivAgent ActiveX Control.