Threat Monitor
Troj.Exploit.HTML.IframeBof
| Aliases: | |
|---|---|
| Pattern: | 200912131430 |
| Threat Type | Propagation Methods | Systems Affected | Risk Level |
|---|---|---|---|
|
|
|
|
This malicious program exploits vulnerability CVE-2009-3658.
AOL SuperBuddy ActiveX control is prone to a remote code-execution vulnerability caused by a memory-corruption error. The vulnerability is caused due to a use-after-free error in the Sb.SuperBuddy.1 ActiveX control (sb.dll). The issue is triggered when a malformed argument is passed to the "SetSuperBuddy()" ActiveX method. By persuading a victim to visit a specially-crafted Web page, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Affected Version: AOL SuperBuddy ActiveX Control 9.x
AOL SuperBuddy ActiveX control is prone to a remote code-execution vulnerability caused by a memory-corruption error. The vulnerability is caused due to a use-after-free error in the Sb.SuperBuddy.1 ActiveX control (sb.dll). The issue is triggered when a malformed argument is passed to the "SetSuperBuddy()" ActiveX method. By persuading a victim to visit a specially-crafted Web page, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Affected Version: AOL SuperBuddy ActiveX Control 9.x


