Title : Hummingbird Deployment Wizard ActiveX Remote Vulnerabilities VUPEN ID : VUPEN/ADV-2008-2857 CVE ID : CVE-2008-4728 CWE ID : CWE-618
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-10-20
Technical Description
Multiple vulnerabilities have been identified in Hummingbird Deployment Wizard 2008, which could be exploited by remote attackers to manipulate data or take complete control of an affected system. These issues are caused due to the insecure methods "Run()", "PerformUpdateAsync()" and "SetRegistryValueAsString()" being provided by the "DeployRun.dll" ActiveX control, which could allow malicious web sites to execute arbitrary applications or manipulate registry keys.