vendor:
Net Resource ActiveX
by:
dookie
7.5
CVSS
HIGH
SEH Exploit
CWE
Product Name: Net Resource ActiveX
Affected Version From: 4.0.0.5
Affected Version To: 4.0.0.5
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Magneto Software Net Resource ActiveX v4.0.0.5 NetConnectionEnum SEH Exploit (Universal)
This exploit targets the Magneto Software Net Resource ActiveX v4.0.0.5 component. It uses a universal SEH exploit to execute arbitrary code, in this case launching the calculator (calc.exe). The original proof of concept was developed by s4squatch and can be found at http://www.exploit-db.com/exploits/12208.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of the affected component or remove the vulnerable ActiveX control from the system.