|
|
|
![]() |
Vulnerability Note VU#155610Groove Virtual Office COM objects may be accessed insecurelyOverviewGroove Virtual Office may allow access restrictions on COM objects to be bypassed. Exploitation may allow an attacker to execute arbitrary code.I. DescriptionGroove Virtual Office provides a collaborative working environment that includes shared documents, databases, and various other tools to facilitate communication and productivity. The Microsoft Component Object Model (COM) provides a means for communication among objects in a Windows environment. Groove Virtual Office uses many COM objects to perform a variety of tasks. A vulnerability exists in Groove that may allow an attacker to bypass Groove's security restrictions and arbitrarily use a COM object's services, such as script execution.Please note that if the access restrictions of a COM object that allows remote access are compromised, that object may be exploited remotely. This vulnerability is addressed in Groove Virtual Office 3.1 build 2338, 3.1a build 2364, and Groove Workspace Version 2.5n build 1871. These updates are available from
References
This vulnerability was reported by US-CERT. This document was written by Jeff Gennari.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||