MS KB870669: ADODB.Stream object from Internet Explorer

high Nessus Plugin ID 12298

Synopsis

The remote host contains a version of IE which may read and write to local files.

Description

The remote host contains a vulnerability in IE. The ADODB.Stream object can be used by a malicious web page to read and write to local files.

An attacker could use this flaw to gain access to the data on the remote host. To exploit this flaw, an attacker would need to set up a rogue website and lure a user on the remote host into visiting it. If the website contains the proper call to the ADODB object, then it may execute data on the remote host.

Solution

Microsoft produced a workaround for this problem.

See Also

https://support.microsoft.com/en-us/help/870669

Plugin Details

Severity: High

ID: 12298

File Name: smb_nt_kb870669.nasl

Version: 1.27

Type: local

Agent: windows

Family: Windows

Published: 7/6/2004

Updated: 11/15/2018

Supported Sensors: Nessus Agent, Nessus

Risk Information

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 6.9

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/o:microsoft:windows, cpe:/a:microsoft:ie

Required KB Items: SMB/Registry/Enumerated

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 9/11/2003

Reference Information

BID: 10514

MSKB: 870669