Vulnerability Note VU#641460
Microsoft Windows fails to properly handle COM objects
OverviewMicrosoft Windows fails to properly handle COM Objects. This vulnerability may allow a remote unauthenticated attacker to execute arbitrary code on a vulnerable system.
I. DescriptionMicrosoft COM
Microsoft COM is a technology that allows programmers to create reusable software components that can be incorporated into applications to extend their functionality. Microsoft COM includes COM+, Distributed COM (DCOM), and ActiveX Controls.
The Problem
Microsoft COM objects are not properly handled. Specifically, users are not properly warned before COM objects are executed.
More information is available in Microsoft Security Bulletin MS06-015.
II. ImpactA remote attacker may be able to execute arbitrary code on a vulnerable system. The attacker-supplied code would be executed with the privileges of the user running Windows Explorer.
III. SolutionApply an Update
This issue is addressed in Microsoft Security Bulletin MS06-015.
Some problems associated with the update (verclsid.exe) and resolutions are described in Microsoft Knowledge Base Article 918165.
Refer to MS06-015
Refer to Microsoft Security Bulletin MS06-015 for workarounds for this vulnerability.
Systems Affected
References
http://www.microsoft.com/technet/security/Bulletin/MS06-015.mspx
http://support.microsoft.com/kb/918165
http://secunia.com/advisories/19606/
Credit
This vulnerability was reported in Microsoft Security Bulletin MS06-015. Microsoft credits NISCC with providing information regarding this vulnerability.
This document was written by Jeff Gennari.
Other Information
| Date Public | 04/11/2006 |
| Date First Published | 04/11/2006 03:28:38 PM |
| Date Last Updated | 05/15/2006 |
| CERT Advisory | |
| CVE Name | CVE-2006-0012 |
| US-CERT Technical Alerts | |
| Metric | 27.00 |
| Document Revision | 15 |
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|