Peaches Posted October 15, 2009 Report Share Posted October 15, 2009 Microsoft Windows ActiveX Controls ATL "OleLoadFromStream()" Vulnerability Extremely critical Description:A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to bypass certain security restrictions and compromise a user's system.The vulnerability is caused due to multiple ActiveX controls using the "OleLoadFromStream()" ATL function in an unsafe manner.This is related to vulnerability #2 in:SA35967 - http://secunia.com/advisories/35967/Successful exploitation allows execution of arbitrary code.NOTE: This vulnerability is reportedly being actively exploited.OS - Microsoft Windows 2000 Advanced ServerMicrosoft Windows 2000 Datacenter ServerMicrosoft Windows 2000 ProfessionalMicrosoft Windows 2000 ServerMicrosoft Windows 7Microsoft Windows Server 2003 Datacenter EditionMicrosoft Windows Server 2003 Enterprise EditionMicrosoft Windows Server 2003 Standard EditionMicrosoft Windows Server 2003 Web EditionMicrosoft Windows Server 2008Microsoft Windows Storage Server 2003Microsoft Windows VistaMicrosoft Windows XP Home EditionMicrosoft Windows XP Professional Secunia advisories - http://secunia.com/advisories/36997/ Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.