Pegasus.Imaging.ImagXpress.ActiveX.File

NamePegasus.Imaging.ImagXpress.ActiveX.File.Delete
Release DateJan 05, 2010
SeverityMedium
ImpactSystem Compromise: Remote attackers can delete arbitrary files in vulnerable systems.
DescriptionThis indicates an attempt to exploit a file-deleting vulnerability in Pegasus Imaging ImagXpress.

The vulnerability is located in the "PegasusImaging.ActiveX.ThumnailXpress1.dll" ActiveX control. It may allow remote attackers to delete arbitrary files in vulnerable systems via a malicious argument to the "CacheFile" method.
Affected ProductsPegasus Imaging Corporation. ImagXpress 8.0
Recommended ActionsSet the kill bit for the following Class ID:
{6277B638-833D-4315-9D78-60FC451DAF07}
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-5320
Reference/shttp://www.securityfocus.com/bid/25948 (BugTraq)
Reference: VID-18062