HTTP: Microsoft HTML Help ActiveX Exploit (2)

This signature detects attempts to exploit a known vulnerability in Microsoft's HTML Help ActiveX control. An attacker can create a specially crafted Web page, which if visited, can allow remote code execution and gain complete control of the victim's system.

Extended Description

The Microsoft HTML Help ActiveX control is prone to a remote code-execution vulnerability. An attacker could exploit this issue to execute code in the context of the user visiting a malicious web page.

Affected Products

Avaya s8100_media_servers,Nortel_networks centrex_ip_client_manager

Short Name
HTTP:STC:CLSID:ACTIVEX:HTML-HP2
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
(2) ActiveX CVE-2007-0214 Exploit HTML Help Microsoft bid:22478
Release Date
02/22/2007
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3339
False Positive
Unknown
Vendors

Nortel_networks

Microsoft

Avaya

CVSS Score

9.3

Found a potential security threat?