HTTP: Sony XCP DRM Uninstaller CLSID Access

This signature detects attempts to exploit several security vulnerabilities against Sony XCP Web-Based Uninstaller ActiveX ClassID. Attackers can exploit these vulnerabilities by crafting a malicious Web site that can add, remove, run any program on your computer, or reboot your computer.

Extended Description

First 4 Internet CodeSupport is susceptible to a remote code execution vulnerability. The CodeSupport package can be told to download, and then execute arbitrary content from remote Web sites. As it fails to verify that the source of the remote content is from a trusted source, attackers may utilize it to download and execute malicious code from arbitrary sources, facilitating the remote compromise of targeted computers.

Affected Products

First4internet codesupport

Short Name
HTTP:STC:CLSID:ACTIVEX:SONY-XCP
Severity
Critical
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Access CLSID CVE-2005-3650 DRM Sony Uninstaller XCP bid:15430
Release Date
11/16/2005
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

First4internet

CVSS Score

9.3

Found a potential security threat?