HTTP: InstallShield 2009 'ISWiAutomation15.dll' File Overwrite

This signature detects attempts to use unsafe ActiveX controls in InstallShield 2009. An attacker can create a malicious Web site containing Web pages with dangerous ActiveX controls, which if accessed by a victim, allows the attacker to gain control of the victim's client browser.

Extended Description

InstallShield 2009 Premier ActiveX control is prone to an arbitrary-file-overwrite vulnerability. Attackers can overwrite arbitrary files on the victim's computer in the context of the vulnerable application (typically Internet Explorer) using the ActiveX control. InstallShield 2009 Premier 15.0.0.53 is vulnerable; other versions may also be affected.

Affected Products

Flexera_software installshield_2009

Short Name
HTTP:STC:ACTIVEX:INST-SHLD-FO
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
'ISWiAutomation15.dll' 2009 File InstallShield Overwrite bid:43857
Release Date
11/11/2010
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Flexera_software

Found a potential security threat?