Overview
Consona (formerly SupportSoft) Intelligent Assistance Suite (IAS) contains a set of vulnerabilities that collectively could allow an attacker to execute arbitrary code on a remote system.
Description
In 2009, Consona acquired SupportSoft's enterprise software assets, including web-based assistance software called Intelligent Assistance Suite (IAS). IAS client components are delivered via ActiveX controls, Netscape-style plugins, or standalone installers. IAS runs on Microsoft Windows platforms. Consona products affected by these vulnerabilities include Consona Live Assistance, Consona Dynamic Agent, Consona Subscriber Assistance, Repair Manager, Consona Subscriber Activiation, and Subscriber Agent. IAS contains vulnerabilities in different components.
Further details are available in Rubén Santamarta's slides from Rooted CON 2010. |
Impact
By convincing a user to view a specially crafted HTML document (web page, HTML email message), an attacker could execute arbitrary code with the privileges of the user, and possibly gain SYSTEM privileges via the Repair Service. |
Solution
Apply patches |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://wintercore.com/en/component/content/article/7-media/18-wintercore-releases-an-advisory-for-consona-products.html
- http://www.wintercore.com/downloads/rootedcon_0day.pdf
- http://www.rootedcon.es/eng/rooted-con-2010/schedule.html
- http://www.consona.com/Content/CRM/Support/SecurityBulletin_April2010.pdf
- http://www.consona.com/news/consonaacquiressupportsoft.aspx
- http://www.consona.com/news/SupportSoftClose.aspx
- http://www.supportsoft.com/Downloads/PDF/brochures/IAS_for_DSP_2008.pdf
- http://support.microsoft.com/kb/240797
Acknowledgements
This information is based on research by Rubén Santamarta. Thanks to Rubén and Consona for following responsible vulnerability disclosure practices.
This document was written by Art Manion.
Other Information
CVE IDs: | None |
Severity Metric: | 15.52 |
Date Public: | 2010-03-19 |
Date First Published: | 2010-05-06 |
Date Last Updated: | 2010-05-18 20:02 UTC |
Document Revision: | 27 |