Stack Overflow in 3rd Party ActiveX Controls affects Multiple Vendor Products
April 30th, 2007 by NewsVulnerabilities were identified in third-party trouble-shooting ActiveX controls, developed by SupportSoft. Two of these controls were signed, shipped and installed with the identified versions of Symantec s consumer products and as part of the Symantec Automated Support Assistant support tool. The vulnerability identified in the Symantec shipped controls could potentially result in a stack overflow requiring user interaction to exploit. If successfully exploited this vulnerability could potentially compromise a user s system possibly allowing execution of arbitrary code or unauthorized access to systemassets with the permissions of the user s browser.
Read More…
Source: Security Team
Leave a Comment