Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
SHARE

CORE IMPACT v7.6 - Exploits Update (Wed Oct 01 2008)

Ultra Office Control ActiveX Exploit

Exploits/Client Side  [Windows]




• Wed Oct 01 2008
The Ultra Office Control ActiveX control (OfficeCtrl.ocx) is vulnerable to a stack-based buffer overflow. By persuading a victim to visit a specially-crafted Web page that passes an overly long string to the HttpUpload() method, a remote attacker could overflow a buffer and execute arbitrary code on the system with the privileges of the current user or cause the victim's browser to crash.

Exploits Vulnerabiltiy: CVE-2008-3878



< Back to Product Updates