Release DateFeb 11, 2010 |
Severityhigh |
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems. |
DescriptionThis indicates an attack attempt to exploit a remote command-execution vulnerability in Windows Script Host Runtime Library.The vulnerability is located in the "wshom.ocx" ActiveX control through misuse of the "Exec" method. It may allow remote attackers to execute arbitrary command in the context of the application using the affected ActiveX control. |
Affected ProductsWindows Script Host Runtime Library |
Recommended ActionsDisable this ActiveX Control by setting its kill bit. |
Coverage IPS
VCM |
Common Vulnerabilities and Exposures (CVE)CVE-2008-4453 |
Reference/shttp://www.exploit-db.com/exploits/14473http://www.exploit-db.com/exploits/11457 http://www.exploit-db.com/exploits/11229 http://www.exploit-db.com/exploits/11151 http://www.securityfocus.com/bid/31504 (BugTraq) |