vendor:
Gateway Weblaunch ActiveX Control
by:
e.b.
7.5
CVSS
HIGH
Insecure Method Exploit
CWE
Product Name: Gateway Weblaunch ActiveX Control
Affected Version From: 1.0.0.1
Affected Version To: 1.0.0.1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP2
2008
Gateway Weblaunch ActiveX Control Insecure Method Exploit
This exploit targets the Gateway Weblaunch ActiveX Control and utilizes an insecure method to launch arbitrary executable files. The exploit uses a buffer overflow vulnerability in the 2nd and 4th parameters of the DoWebLaunch method. By passing specially crafted parameters, an attacker can escape the intended directory and execute arbitrary commands on the target system. In this example, the exploit launches the Windows Calculator (calc.exe) as a proof of concept.
Mitigation:
To mitigate this vulnerability, it is recommended to update the Gateway Weblaunch ActiveX Control to a patched version that addresses the insecure method. Additionally, users should exercise caution when interacting with untrusted websites or ActiveX controls.