vendor:
ArGoSoft Mail Server
by:
callAX
N/A
CVSS
N/A
Arbitrary Data Write & Remote Code Execution
CWE
Product Name: ArGoSoft Mail Server
Affected Version From: 1.8.9.1
Affected Version To: 1.8.9.1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP1/SP2 french/english with IE 6.0 / 7.0
2007
mlsrvx.dll 1.8.9.1 ArGoSoft Mail Server Arbitrary Data Write & Remote Code Execution
The Add & SaveToFile methods in mlsrvx.dll in ArGoSoft Mail Server allow remote attackers to write arbitrary data and execute arbitrary code via crafted HTML pages.
Mitigation:
Activate the Kill bit zero in clsid:3F06B376-8DB8-49D1-8BF8-D4C070EFEBA5, Unregister mlsrvx.dll using regsvr32.