Saturday, May 31, 2008

Creative Software AutoUpdate Engine ActiveX Stack-Overflow Exploit

A vulnerability has been reported in Creative Software AutoUpdate Engine ActiveX Control, which can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to a boundary error within the Creative Software AutoUpdate Engine ActiveX control (CTSUEng.ocx) when handling certain unspecified properties or methods. This can be exploited to cause a stack-based buffer overflow when a user is tricked into visiting a malicious website.

Successful exploitation may allow execution of arbitrary code.

--------------------------

Public Exploit
http://www.milw0rm.com/exploits/5681

No comments:

Post a Comment