HTTP: VMLRender ActiveX

This signature detects attempts to exploit a known vulnerability in Microsoft Internet Explorer. Attackers can create malicious Web pages containing dangerous Class ID, which if accessed by a victim, allows the attacker to gain control of the victim's client browser.

Extended Description

Microsoft Windows is prone to a buffer-overrun vulnerability that arises because of an error in the processing of Vector Markup Language documents. An attacker can exploit this issue to execute arbitrary code within the context of the affected application.

Affected Products

Avaya s8100_media_servers,Microsoft windows_2000_server

Short Name
HTTP:STC:CLSID:ACTIVEX:VML-AX
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
ActiveX CVE-2007-0024 VMLRender bid:21930
Release Date
11/15/2007
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3339
False Positive
Unknown
Vendors

Nortel_networks

Microsoft

Avaya

CVSS Score

9.3

Found a potential security threat?