IBM Lotus iNotes Upload Module ActiveX Control Attachment_Times() Method Buffer Overflow

high Nessus Plugin ID 59685

Synopsis

The remote Windows host has an ActiveX control that is affected by a buffer overflow vulnerability.

Description

The Lotus iNotes Upload Module ActiveX Control is installed on the remote Windows host. The installed version of the control is affected by a buffer overflow vulnerability in the Attachment_Times() method.
By tricking a victim into visiting a specially crafted page, an attacker may be able to execute arbitrary code on the host.

Solution

Either set the kill bit for the control or see the vendor's advisory for an updated control.

See Also

https://www.zerodayinitiative.com/advisories/ZDI-12-132/

https://seclists.org/fulldisclosure/2012/Aug/61

http://www-304.ibm.com/support/docview.wss?uid=swg21596862

Plugin Details

Severity: High

ID: 59685

File Name: lotus_notes_upload_activex_bof.nasl

Version: 1.12

Type: local

Agent: windows

Family: Windows

Published: 6/19/2012

Updated: 11/15/2018

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.4

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 7.7

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/a:ibm:lotus_notes

Required KB Items: SMB/Registry/Enumerated

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 5/31/2012

Vulnerability Publication Date: 5/31/2012

Exploitable With

Core Impact

Metasploit (IBM Lotus iNotes dwa85W ActiveX Buffer Overflow)

Reference Information

CVE: CVE-2012-2175

BID: 53879