This application requires Javascript for optimal performance.

MS.IE.Wshom.Exec.ActiveX.Access

Release Date

Feb 11, 2010

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt to exploit a remote command-execution vulnerability in Windows Script Host Runtime Library.

The vulnerability is located in the "wshom.ocx" ActiveX control through misuse of the "Exec" method. It may allow remote attackers to execute arbitrary command in the context of the application using the affected ActiveX control.

Affected Products

Windows Script Host Runtime Library

Recommended Actions

Disable this ActiveX Control by setting its kill bit.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2008-4453

Reference/s

http://www.exploit-db.com/exploits/14473
http://www.exploit-db.com/exploits/11457
http://www.exploit-db.com/exploits/11229
http://www.exploit-db.com/exploits/11151
http://www.securityfocus.com/bid/31504 (BugTraq)

Reference: VID-18130