Overview
The ActiveX installer for Adobe Macromedia Shockwave contains a buffer overflow, which may allow a remote unauthenticated attacker to execute arbitrary code on a vulnerable system.
Description
Shockwave Player Adobe Macromedia Shockwave Player is software that plays active web content developed in Macromedia Director. Shockwave Player is available as an ActiveX control for Internet Explorer and as a plug-in for other web browsers. |
Impact
By convincing a user to view a specially crafted HTML document (for example, a web page) and to accept the Shockwave Player ActiveX installer prompt, an attacker may be able to execute arbitrary code with the privileges of the user. |
Solution
Do not install ActiveX controls from untrusted web sites |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This vulnerability was disclosed by Adobe, who in turn credit Zero Day Initiative with reporting the vulnerability.
This document was written by Will Dormann.
Other Information
CVE IDs: | CVE-2005-3525 |
Severity Metric: | 3.88 |
Date Public: | 2006-02-23 |
Date First Published: | 2006-02-28 |
Date Last Updated: | 2006-02-28 18:57 UTC |
Document Revision: | 10 |