HTTP: Microsoft Office Unsafe ActiveX Control

This signature detects attempts to use unsafe ActiveX controls in Microsoft Office. An attacker can create a malicious Web site containing Web pages with dangerous ActiveX controls, which if accessed by a victim, allows the attacker to gain control of the victim's client browser.

Extended Description

Microsoft Visual Studio is prone to a remote code-execution vulnerability in the Active Template Library (ATL). Remote attackers can exploit this issue to execute arbitrary code with the privileges of the user running an application built against the affected library. Failed exploit attempts will result in a denial-of-service condition.

Affected Products

Nortel_networks self-service_media_processing_server,Microsoft windows_vista

Short Name
HTTP:STC:ATL:MSOFFICE-AX
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
ActiveX CVE-2009-2493 Control Microsoft Office Unsafe
Release Date
10/13/2009
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Nortel_networks

Hp

Suse

Microsoft

Pardus

CVSS Score

9.3

Found a potential security threat?