Overview
SetupCtl 1.0 Type Library is a safe-for-scripting ActiveX control that contains a remotely exploitable buffer overflow. This control ships with Microsoft Internet Explorer 4.01 and 5.
Description
SetupCtl 1.0 Type Library is a safe-for-scripting ActiveX control that contains a remotely exploitable buffer overflow. The INSTALLNOW routine fails to check the buffer size of the DistUnit variable. This control ships with Microsoft Internet Explorer 4.01 and 5. The CLSID for this control is {F72A7B0E-0DD8-11D1-BD6E-00AA00B92AF1}. |
Impact
An attacker may exploit the buffer overflow to execute arbitrary commands. |
Solution
Apply the patch from Microsoft Security Bulletin MS99-37. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Thanks to Shane Hird for reporting this vulnerability.
This document was written by Jason A Rafail and Cory F. Cohen.
Other Information
CVE IDs: | CVE-1999-0702 |
Severity Metric: | 17.62 |
Date Public: | 1999-09-10 |
Date First Published: | 2002-10-01 |
Date Last Updated: | 2002-10-11 19:06 UTC |
Document Revision: | 15 |