This application requires Javascript for optimal performance.

HTTP.Ultra.Crypto.SaveToFile.ActiveX.Remote.File.Overwrite

Release Date

Jan 05, 2012

Severity

critical

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attempt to exploit a Code Execution vulnerability in Ultra Crypto Component.

The vulnerability is located in the "CryptoX.dll" ActiveX control with overlay long argument to the "SaveToFile" method. It may allow remote attackers to download and install arbitrary files in vulnerable systems.

Affected Products

Ultra Shareware Ultra Crypto Component 0

Recommended Actions

Set the kill bit for the following classid:
{FD22F3AE-1450-4BDC-ADBE-6AF210A78C2C}

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2007-4902

Reference/s

http://securitytracker.com/alerts/2007/Sep/1018675.html
http://www.milw0rm.com/exploits/4388
http://www.securityfocus.com/bid/25611 (BugTraq)

Reference: VID-30515