SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#673134

Microsoft MSN "Hrtbeat.ocx" ActiveX control contains unspecified vulnerability

Overview

A vulnerability exists in the Microsoft MSN "Hrtbeat.ocx" ActiveX control.

I. Description

ActiveX is a technology that allows programmers to create reusable software components that can be incorporated into applications to extend their functionality. Microsoft Internet Explorer provides support for the ActiveX technology. There is a vulnerability in the Microsoft MSN "Hrtbeat.ocx" ActiveX control. This control provides support for online gaming when visiting MSN related sites. The following information is provided in MS04-038:

    This update sets the kill bit for the Hrtbeat.ocx ActiveX control. This control implements support for online gaming in MSN related sites. Internet Explorer no longer supports this control. This control has been found to contain a security vulnerability. To help protect customers who have this control installed, this update prevents the control from running or from being reintroduced onto users’ systems by setting the kill bit for the control. For more information about kill bits, see Microsoft Knowledge Base Article 240797.

For information on preventing ActiveX controls from running in Internet Explorer, please refer to the Microsoft article "How to Stop an ActiveX Control from Running in Internet Explorer."

II. Impact

The impact of this vulnerability is not known. In the case of a buffer overflow, a remote attacker could execute arbitrary code with the privileges of the user running Internet Explorer. The attacker may also be able to cause a denial of service.

III. Solution

Apply Patch

Apply the appropriate patch referenced in Microsoft Security Bulletin MS04-038.

Systems Affected

VendorStatusDate NotifiedDate Updated
Microsoft CorporationVulnerable19-Oct-2004

References


http://www.nextgenss.com/advisories/heartbeat.txt
http://www.microsoft.com/technet/security/bulletin/MS04-038.mspx
http://support.microsoft.com/default.aspx?id=240797
http://msdn.microsoft.com/workshop/components/activex/controls.asp
http://www.microsoft.com/com/tech/ActiveX.asp
http://securitytracker.com/alerts/2004/Oct/1011678.html
http://secunia.com/advisories/12806/

Credit

This vulnerability was reported by Microsoft. Microsoft credits NGS Software Ltd. for discovering the vulnerability.

This document was written by Damon Morda and Art Manion.

Other Information

Date Public:2004-10-13
Date First Published:2004-10-19
Date Last Updated:2004-12-06
CERT Advisory: 
CVE-ID(s):CAN-2004-0978
NVD-ID(s):CAN-2004-0978
US-CERT Technical Alerts: 
Metric:3.19
Document Revision:17

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2004 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader