>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>Software that uses it:> Microsoft Internet Explorer 5.01
Microsoft Internet Explorer 5.5
Microsoft Internet Explorer 6.x
Microsoft Visual Studio 6 Enterprise
Microsoft Visual Studio 6 Professional
>>>>>>>Description:
A vulnerability has been identified in a Microsoft ActiveX plugin called MCIWNDX.OCX, which possibly allows malicious HTML documents to execute arbitrary code on a vulnerable system.
The problem is that a property called "Filename" isn't properly verified allowing malicious websites or HTML emails to cause a buffer overflow by supplying an overly long string. This could potentially be exploited to execute arbitrary code on the system.
This plugin is part of Visual Studio version 6. However, since the plugin is digitally signed by Microsoft, it may be silently installed through Internet Explorer by any website.
Solution:
Remove the ActiveX plugin if it is installed.
Configure Internet Explorer to prompt before accepting or executing any ActiveX plugins or block the ActiveX plugin using your proxy server.
>>>>>>Hope this helps, if so please accept.>>>
Edited by FirstHogman on January 7 2006 at 11:23 AM
If more information is needed, please ask me.
Hope this helps, an accept would be appreciated.
Firsthogman
Love them Harley's