Overview
The SolidWorks sldimdownload ActiveX control contains methods that can allow a remote, unauthenticated attacker to run arbitrary code on a vulnerable system.
Description
SolidWorks provides 3D CAD software solutions. The SolidWorks sldimdownload ActiveX control is provided by the file sldimdownload.dll. It contains a method called Run(), which takes installerpath and applicationarguments parameters. This method can be used to execute arbitrary applications that may reside on remote servers. |
Impact
By convincing a victim to view an HTML document (web page, HTML email, or email attachment), an attacker could run arbitrary code with the privileges of the user running IE. |
Solution
Install an update This issue has been addressed in the sldimdownload ActiveX control version 16,0,0,1. This version restricts the web domains that can use the control. To update, close all Internet Explorer windows. Go to %windir%\downloaded program files . Right click on sldimdownloadiface and select update. Please see the SolidWorks technical document for more information. |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This vulnerability was reported by Will Dormann of CERT/CC.
This document was written by Will Dormann.
Other Information
CVE IDs: | CVE-2007-1684 |
Severity Metric: | 0.64 |
Date Public: | 2007-04-03 |
Date First Published: | 2007-04-03 |
Date Last Updated: | 2007-04-10 20:50 UTC |
Document Revision: | 9 |