vendor:
IMMenuShellExt ActiveX Control
by:
Umesh Wanve
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: IMMenuShellExt ActiveX Control
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 2000 SP4 Server English, Windows 2000 SP4 Professional English
2007
IncrediMail IMMenuShellExt ActiveX Control Buffer Overflow Exploit
This exploit triggers a buffer overflow vulnerability in the IncrediMail IMMenuShellExt ActiveX Control, allowing an attacker to execute arbitrary code on the vulnerable machine. The exploit opens the Calculator application as a proof of concept.
Mitigation:
Apply the latest patch or update from the vendor to fix the buffer overflow vulnerability.