|
|
ACTi Network Video Recorder ActiveX File Deletion and Creation Vulnerability
|
A vulnerability has been identified in ACTi Network Video Recorder (NVR), which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. This issue is caused by errors in the "nvUtility.Utility.1" (nvUtility.dll) ActiveX control that does not restrict access to the "SaveXMLFile()" and "DeleteXMLFile()" methods, which could be exploited by attackers to create or delete arbitrary files on a vulnerable system and execute arbitrary code by tricking a user into visiting a malicious web page.
ACTi Network Video Recorder (NVR) version 2.0.30 SP2 and prior
Set a kill bit for the CLSID {A0D43FB0-116B-47AB-80FB-6DCFA92A03E3}.
VUPEN Security is not aware of any vendor-supplied patch.
http://www.vupen.com/english/advisories/2007/2993
Vulnerability reported by shinnai.
2007-08-28 : Initial release
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
|
|
|
Monthly Statistics |
 |
|
|
|
| |
|
Try VUPEN
VNS |
 |
|
 |
|
| |
|
 |
| |
|
|
|
|