vendor:
InTrust
by:
7.5
CVSS
HIGH
ArDoc.dll ActiveX Control Remote File Creation / Overwrite
CWE
Product Name: InTrust
Affected Version From: Quest InTrust 10.4.x
Affected Version To: Not specified
Patch Exists: NO
Related CWE:
CPE: a:quest:intrust:10.4
Platforms Tested: Windows, Unix, Linux
Quest InTrust 10.4.x ReportTree and SimpleTree Classes ArDoc.dll ActiveX Control Remote File Creation / Overwrite
The Quest InTrust 10.4.x ReportTree and SimpleTree classes in ArDoc.dll ActiveX Control allow arbitrary file creation and overwrite through the SaveToFile method. This vulnerability can be exploited to remotely execute code if the attacker can control the file content.
Mitigation:
It is recommended to update to a patched version of the software or disable the affected ActiveX control.