HTTP: Daum Game Unsafe ActiveX Control

This signature detects attempts to use unsafe ActiveX controls in Daum Game. Attacker can use the unsafe Activex method hosted at a website, and can gain access to client system.

Extended Description

Buffer overflow in the IconCreate method in an ActiveX control in the DaumGame ActiveX plugin 1.1.0.4 and 1.1.0.5 allows remote attackers to execute arbitrary code via a long string, as exploited in the wild in January 2014.

Affected Products

Daum_communications daumgame_activex_control

References

CVE: CVE-2013-7246

Short Name
HTTP:STC:ACTIVEX:DAUM-GAME
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
ActiveX CVE-2013-7246 Control Daum Game Unsafe
Release Date
03/28/2017
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Daum_communications

CVSS Score

9.3

Found a potential security threat?