HTTP: Microsoft Windows Media Encoder 9 Unsafe ActiveX Control

This signature detects attempts to exploit a known vulnerability in Windows Media Encoder 9. An attacker can create a malicious Web site with Web pages containing dangerous ActiveX calls, which if accessed by a victim, allows the attacker to gain control of the victim's client browser.

Extended Description

The Microsoft Windows Media Encoder 9 ActiveX control is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input. An attacker can exploit this issue to execute arbitrary code in the context of an application using the affected ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.

Affected Products

Nortel_networks self-service_speech_server,Nortel_networks media_processing_svr_100

Short Name
HTTP:STC:ACTIVEX:WMEX
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
9 ActiveX CVE-2008-3008 Control Encoder Media Microsoft Unsafe Windows bid:31065
Release Date
09/18/2008
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3729
False Positive
Unknown
Vendors

Nortel_networks

Hp

Microsoft

CVSS Score

9.3

Found a potential security threat?