This application requires Javascript for optimal performance.

Awingsoft.Winds3d.Command.Execution

Release Date

Sep 17, 2009

Severity

critical

Impact

System compromise

Description

This indicates an attack attempt against a command-execution vulnerability in the Awingsoft Awakening Winds3D Viewer plugin.

The vulnerability is caused by an error when the vulnerable software handles a malicious Winds3D scene. It allows a remote attacker to execute arbitrary command by enticing the user to visit a malicious website.

Affected Products

Awingsoft Awakening Winds3D Viewer plugin 3.5.0.0, 3.0.0.5

Recommended Actions

Temporarily disable the affected plugin.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2009-2386

Reference/s

http://www.securityfocus.com/bid/35595 (BugTraq)

Reference: VID-17695