This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Multiple ActiveX vulnerabilities alert

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

> http://isc.sans.org/diary.html?storyid=3929
Last Updated: 2008-02-04 19:52:11 UTC (References Symantec info below)

- http://www.symantec.com/avcenter/threatcon/
"…A total of six buffer-overflow vulnerabilities that affect a number of widely distributed ActiveX controls have been disclosed in the past week. On February 3, 2008, additional high-profile ActiveX overflows were released by the same researcher who recently disclosed vulnerabilities in Aurigma Imaging Technology, MySpace, and Facebook image-upload ActiveX functions. Although very similar to the image-upload issues disclosed on January 31, 2008, these new ImageUploader issues are distinct and affect different properties. Note that the MySpace ImageUploader library has not been reported to be affected by these new vulnerabilities*. The remaining two vulnerabilities affect Yahoo! Jukebox MediaGrid and DataGrid ActiveX controls. We are unaware of any public exploitation of these vulnerabilities. However, the Symantec DeepSight team has confirmed that these issues can be used to execute code or crash the vulnerable applications. Judging by the wide distribution of these controls, we assume that these issues will be used by attackers and we are monitoring for such developments. Customers are advised to:
1. Set the kill bit for the following CLSIDs as soon as possible:
Aurigma: CLSID 6E5E167B-1566-4316-B27F-0DDAB3484CF7 ('ImageUploader4.ocx') ***
Aurigma: CLSID BA162249-F2C5-4851-8ADC-FC58CB424243 ('ImageUploader5') ***
Facebook: CLSID 5C6698D9-7BE4-4122-8EC5-291D84DBD4A0 **
Yahoo! MediaGrid: CLSID 22FD7C0A-850C-4A53-9821-0B0915C96139
Yahoo! DataGrid: CLSID 5F810AFC-BB5F-4416-BE63-E01DD117BD6C2
2. Take extreme caution when browsing the web.
3. Relay cautionary information to your users.
4. Ensure that browsers are configured with the highest security settings. Please see the following Microsoft support document for instructions on how to disable the ActiveX components: How to stop an ActiveX control from running in Internet Explorer
http://support.microsoft.com/kb/240797 …"

* Exception: http://secunia.com/advisories/28715

** Exception: http://secunia.com/advisories/28713/

*** Exception: Aurigma Image Uploader 4.x, Aurigma Image Uploader5.x
http://blogs.aurigma.com/post/2008/01/Anot…-not-again.aspx

:ph34r:
More references and updates…

MySpace Uploader Control ActiveX…
- http://secunia.com/advisories/28715
Last Update: 2008-02-05
Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch <<<
Software: MySpace Uploader Control 1.x …
Solution: Update to version 1.0.0.6.
Changelog:
2008-02-05: Updated "Solution" section.

Yahoo! Music Jukebox ActiveX…
- http://secunia.com/advisories/28757/
Release Date: 2008-02-04
Critical: Extremely critical
Impact: System access
Where: From remote
Solution Status: Unpatched <<<
Software: Yahoo! Music Jukebox 2.x …

Aurigma Image Uploader ActiveX…
- http://secunia.com/advisories/28733/
Last Update: 2008-02-05
Solution Status: Vendor Patch <<<

Aurigma Image Uploader ActiveX…
- http://secunia.com/advisories/28707/
Release Date: 2008-02-04
Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Unpatched <<<
…The vulnerability is confirmed in ImageUploader5.ocx version 5.0.15.0, ImageUploader4.ocx version 4.6.11.0 and reported in versions 4.6.17.0, 4.5.70.0, 4.5.126.0, and [removed]. Other versions may also be affected.
Solution: Set the kill-bit for the affected ActiveX control.
Original Advisory:
http://lists.grok.org.uk/pipermail/full-di…ary/060025.html

.
FYI…

Unpatched Yahoo Vulnerability being Exploited in the Wild
- http://preview.tinyurl.com/2chamc
February 5, 2008 (Symantec Security Response Weblog) - "Yesterday an exploit was released for the Yahoo! Music Jukebox AddImage Function ActiveX Remote Buffer Overflow Vulnerability… our honeypots are already picking up exploitation of it in the wild. So far the exploits that we have seen used in the wild have been carbon copies of the public exploit. I suspect that it won’t take long before the exploit is wrapped in an encoder in an attempt to make detection more difficult, however. A set of similar vulnerabilities in Yahoo! Jukebox were announced on Friday and although I have not yet seen these being exploited, I am sure it is only a matter of time…"

:ph34r:
FYI…

Yahoo! Music Jukebox ActiveX Control Buffer Overflows
- http://secunia.com/advisories/28757/
Last Update: 2008-02-07
Critical: Extremely critical
Impact: System access
Where: From remote
Solution Status: Unpatched
Software: Yahoo! Music Jukebox 2.x …
NOTE: Working exploit code is publicly available.
The vulnerabilities are confirmed in Yahoo! Music Jukebox version 2.2.2.056. Other versions may also be affected…
Solution: Set the kill-bit for the affected ActiveX controls.
Other References:
US-CERT VU#101676: http://www.kb.cert.org/vuls/id/101676
US-CERT VU#340860: http://www.kb.cert.org/vuls/id/340860
———————
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0623
release date: 2/6/2008 - YMP Datagrid ActiveX control (datagrid.dll)
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0624
release date: 2/6/2008 - YMP Datagrid ActiveX control (datagrid.dll)
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0625
release date: 2/6/2008 - MediaGrid ActiveX control (mediagrid.dll)
FYI…

MySpace Uploader ActiveX Exploited in the Wild
- http://preview.tinyurl.com/22vn4d
February 7, 2008 (Symantec Security Response Weblog) - "Yesterday our honeypots picked up a browser attack toolkit that I had not encountered before. This toolkit uses dynamic function and variable names and wraps its exploits in two levels of dynamic encoding. Finding a new toolkit on our honeypots always piques my interest as a new toolkit often yields new exploit payload. Lo and behold, once the encoder layers are peeled away, the toolkit is found to contain an exploit for the MySpace Uploader 'MySpaceUploader.ocx' ActiveX Control Buffer Overflow that was announced on the 31st of January*…"
* http://securityresponse.symantec.com/avcen…igs/s50096.html
"…issue leads to a crash in 'MySpaceUploader.ocx' 1.0.0.4 and 1.0.0.5…"

> http://secunia.com/advisories/28715
Solution: Update to version 1.0.0.6.

:ph34r:
FYI…

New Facebook Photo Uploader ActiveX Vulnerability
- http://atlas.arbor.net/briefs/index#-1074023979
(…Scroll down to):
Severity: Elevated Severity
Published: Wednesday, February 13, 2008 18:57
Facebook Photo Uploader ActiveX control is prone to a buffer-overflow vulnerability. Attackers can exploit this issue and execute arbitrary code in the context of the browser. Exploit is available. Until this issue fixed by the vendor, a workaround would be to set the kill bit for the ActiveX control.
Analysis: The ActiveX control in question is ImageUploader4.1.ocx. The 'FileMask' method is vulnerable. Attackers need to make a user view a crafted HTML to exploit this issue. A workaround would be to set the kill bit for the Control till it is fixed…

:ph34r:
FYI…

- http://blog.washingtonpost.com/securityfix…acebook_my.html
February 23, 2008 - "If you use Internet Explorer (versions 6 or 7) to browse the Web, listen up: Criminals are starting to exploit security holes in several widely installed IE plug-ins to plant invasive software when users are coerced or tricked into visiting one of several Web sites. In an alert posted Friday evening, security software vendor Symantec said it is seeing malicious Web sites popping up trying to exploit vulnerabilities in a set of ActiveX controls produced by Aurigma, a technology company whose image transfer browser plug-in is licensed and distributed by a number of major Web sites to help IE users upload pictures. Currently, Facebook.com and MySpace.com are among the biggest distributors of this ActiveX plug-in, but they are hardly the only ones… The malicious Web sites identified by Symantec actually redirects visitors to a fake MySpace.com login page in an attempt to steal MySpace credentials, all while trying the various plug-in exploits quietly in the background… The sites all download a series of executable programs, including some that Symantec said appear to be placeholders for whatever nasties the bad guys want to stuff in there later. The company said it is still in the process of analyzing the programs to see what they do, but it's doubtful they will turn out to be harmless… If you haven't checked out the free, easy-to-use fixit tool* released by incident handlers at the SANS Internet Storm Center, please do so now. The simple, graphical program sets a marker in the Windows registry so that if the vulnerable ActiveX components are installed, then the operating system will not let anyone or anything make use or activate those components… If you ever want to -undo- any part of what (the tool does), run the tool again and uncheck the relevant boxes and hit "set."
* http://isc.sans.org/diary.html?storyid=3931
Last Updated: 2008-02-05 19:48:41 UTC …(Version: 3)
(Direct link for tool - http://handlers.sans.org/tliston/KillBitGui-Feb08.exe )

:ph34r: