Advisories Blog | G5 Cyber Security

cadsm-activex.txt

CA products that implement the DSM gui_cm_ctrls ActiveX control contain a vulnerability that can allow a remote attacker to cause a denial of service or execute arbitrary code. The vulnerability is due to insufficient verification of function arguments by the gui_cm_ctrls control. An attacker can execute arbitrary code under the context of the user running the web browser.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/65588/cadsm-activex.txt

Source: https://packetstormsecurity.com/files/65588/cadsm-activex.txt.html

Exit mobile version