>> SupportSoft Multiple ActiveX Control Arguments Handling Buffer Overflow Vulnerabilities
Title : SupportSoft Multiple ActiveX Control Arguments Handling Buffer Overflow Vulnerabilities VUPEN ID : VUPEN/ADV-2007-0703 CVE ID : CVE-2006-6490
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-02-23
Technical Description
Multiple vulnerabilities have been identified in various SupportSoft ActiveX controls, which could be exploited by remote attackers to take complete control of an affected system. These issues are due to buffer overflow errors in the SmartIssue, RemoteAssist, and Probe controls when handling malformed arguments passed to certain methods, which could be exploited by remote attackers to execute arbitrary commands by tricking a user into visiting a specially crafted web page.