AccueilRessources › Gestionnaire de menaces

Threat Monitor

 

« Back to list

Troj.Exploit.JS.MSIE.A

 
Aliases:
Pattern:201102131330
Threat Type Propagation Methods Systems Affected Risk Level
  • Exploit
  • Exploit Vulnerability
  • Windows NT
  • Windows XP
  • Windows 2000
  • Windows 95/98/ME
  • MS-DOS
  • Other
  • Low
 
The Microsoft WMI Administrative Tools ActiveX control (WBEMSingleView.ocx) is prone to a remote code execution vulnerability.
The vulnerability is due to the "AddContextRef()" and "ReleaseContext()" methods in the WMI Object Viewer Control (WBEM.SingleViewCtrl.1) with the CLSID:2745E5F5-D234-11D0-847A-00C04FD7BB08 using a value passed in the "lCtxHandle" parameter as an object pointer. By persuading a victim to visit a specially-crafted Web page, a remote attacker could exploit this vulnerability to execute code or cause the victim's browser to crash.

Affected: Microsoft WMITOOLS 1.1
Microsoft WMI Object Viewer ActiveX Control 1.x

Back to Top

Partenaires PowerShift

Avec le programme PowerShift, l'univers Netgear s'ouvre à vous.

Page d'identification :
http://www.powershift.fr/