MS 2736233: Update Rollup for ActiveX Kill Bits (2736233)

High Nessus Plugin ID 62045


The remote Windows host is missing an update that disables selected ActiveX controls.


The remote Windows host is missing one or more kill bits for ActiveX controls that are known to contain vulnerabilities.

If any of these ActiveX controls are ever installed on the remote host, either now or in the future, they would expose the host to various security issues.

Note that the affected controls are from a third-party vendor that has asked Microsoft to prevent their controls from being run in Internet Explorer.


Microsoft has released a set of patches for Windows XP, 2003, Vista, 2008, 7, and 2008 R2.

See Also

Plugin Details

Severity: High

ID: 62045

File Name: smb_kb_2736233.nasl

Version: $Revision: 1.10 $

Type: local

Agent: windows

Family: Windows

Published: 2012/09/11

Modified: 2017/08/30

Dependencies: 13855, 57033

Risk Information

Risk Factor: High


Base Score: 9.3

Temporal Score: 7.7

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:F/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/o:microsoft:windows

Required KB Items: SMB/MS_Bulletin_Checks/Possible

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2012/09/11

Vulnerability Publication Date: 2012/09/11

Reference Information

CVE: CVE-2012-2493, CVE-2012-2494, CVE-2012-2495, CVE-2012-2496

BID: 54107, 54108

OSVDB: 83096, 83159

MSKB: 2736233