This script is Copyright (C) 2012-2017 Tenable Network Security, Inc.
The remote Windows host has an ActiveX control that is affected by
multiple buffer overflow vulnerabilities.
The Cisco Linksys PlayerPT ActiveX Control is installed on the remote
Windows host. The installed version of the control is affected by the
following buffer overflow vulnerabilities in the SetSource() method :
- The 'base64string' argument is not properly sanitized.
- The 'sURL' argument is not properly sanitized if the
'sFrameType' argument is set to 'mpeg'.
By tricking a victim into visiting a specially crafted page, an
attacker may be able to execute arbitrary code on the host.
See also :
Set the kill bit for the control as there is no fix at the time of
Risk factor :
High / CVSS Base Score : 9.3
CVSS Temporal Score : 7.7
Public Exploit Available : true