vendor:
Chilkat Zip ActiveX Component
by:
shinnai
7.5
CVSS
HIGH
Insecure Methods
CWE
Product Name: Chilkat Zip ActiveX Component
Affected Version From: ChilkatZip2.dll v. 12.4.2.0
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP Professional SP2 with Internet Explorer 7
2007
Chilkat Software Chilkat Zip ActiveX Component (ChilkatZip2.dll v. 12.4.2.0) ‘SaveLastError()’ and ‘WriteExe()’ Insecure Methods
The 'SaveLastError()' and 'WriteExe()' methods in Chilkat Zip ActiveX Component (ChilkatZip2.dll v. 12.4.2.0) allow an attacker to overwrite the system.ini file, potentially causing the system to not restart properly. This exploit is for educational purposes only and should be used at your own risk.
Mitigation:
Make a copy of the system.ini file before running this exploit to prevent any damage. Update to a newer version of the Chilkat Zip ActiveX Component that addresses this vulnerability.