HTTP: Quest vWorkspace pnllmcli.dll ActiveX

This signature detects attempts to use unsafe ActiveX controls in Quest vWorkspace. An attacker can create a malicious Web site containing Web pages with dangerous ActiveX controls, which if accessed by a victim, allows the attacker to gain control of the victim's client browser.

Extended Description

Quest vWorkspace ActiveX control is prone to an arbitrary-file-overwrite vulnerability. Attackers can overwrite arbitrary files on the victim's computer in the context of the vulnerable application that is using the ActiveX control (typically Internet Explorer). vWorkspace 7.5 is vulnerable; other versions may also be affected.

Affected Products

Quest_software vworkspace

Short Name
HTTP:STC:ACTIVEX:QUEST-PNLLMCLI
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
ActiveX Quest bid:52917 pnllmcli.dll vWorkspace
Release Date
04/11/2012
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Quest_software

Found a potential security threat?