MS.IE.Wshom.Exec.ActiveX.Access

Release DateFeb 11, 2010
SeverityHigh
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
DescriptionThis indicates an attack attempt to exploit a remote command-execution vulnerability in Windows Script Host Runtime Library.

The vulnerability is located in the "wshom.ocx" ActiveX control through misuse of the "Exec" method. It may allow remote attackers to execute arbitrary command in the context of the application using the affected ActiveX control.
Affected ProductsWindows Script Host Runtime Library
Recommended ActionsDisable this ActiveX Control by setting its kill bit.
Reference/shttp://www.exploit-db.com/exploits/11151
http://www.exploit-db.com/exploits/11229
Reference: VID-18130