Vulnerability CVE-2009-3735


Published: 2010-02-11   Modified: 2012-02-13

Description:
The ActiveScan Installer ActiveX control in as2stubie.dll before 1.3.3.0 in PandaActiveScan Installer 2.0 in Panda ActiveScan downloads software in an as2guiie.cab archive located at an arbitrary URL, and does not verify the archive's digital signature before installation, which allows remote attackers to execute arbitrary code via a URL argument to an unspecified method.

Type:

CWE-94

(Improper Control of Generation of Code ('Code Injection'))

CVSS2 => (AV:N/AC:M/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
9.3/10
10/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Panda -> Panda activescan 

 References:
http://www.kb.cert.org/vuls/id/869993
http://www.kb.cert.org/vuls/id/MAPG-7QPKL3
http://www.securityfocus.com/bid/38067
http://www.vupen.com/english/advisories/2010/0354
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-008

Copyright 2024, cxsecurity.com

 

Back to Top