CA.ETrust.PestPatrol.Ppctl.Dll.ActiveX

NameCA.ETrust.PestPatrol.Ppctl.Dll.ActiveX.Access
Release DateNov 02, 2009
SeverityCritical
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
DescriptionThis indicates an attempt to exploit a code execution vulnerability in CA eTrust PestPatrol.

The vulnerability is located in the "ppctl.dll" ActiveX control through misuse of the "Initialize" method. It may allow remote attackers to execute arbitrary code in vulnerable systems.
Affected ProductsCA eTrust PestPatrol with ppctl.dll (5.6.7.9)
Recommended ActionsSet the kill bit for the following CLSID:

{5e644c49-f8b0-4e9a-a2ed-5f176bb18ce6}
Reference/shttp://www.my-etrust.com/Extern/RoadRunner/PestScan/scan.htm
Reference: VID-17847