This application requires Javascript for optimal performance.

MS.CapiCom.Utilities.ActiveX.GetRandom.Integer.Overflow.DoS

Release Date

Oct 06, 2011

Severity

medium

Impact

System Compromise: Remote attackers may be able to execute arbitrary code.

Description

This indicates an attempt to exploit a Memory Corruption vulnerability in Microsoft's CapiCom Utilities ActiveX Control.

The vulnerability can be exploited through misuse of the "GetRandom" method. It may allow remote attackers to execute arbitrary code in the context of the application using the affected ActiveX control. Failed exploit attempts will likely cause the program to crash, resulting in a Denial of Service condition.

Affected Products

Microsoft's CapiCom Utilities ActiveX Control

Recommended Actions

Currently we are not aware of any vendor supplied patch for this issue.

Coverage

IPS
VCM

Reference: VID-29348