Vulnerability Note VU#810772
Microsoft Agent fails to properly handle specially crafted .ACF files
OverviewMicrosoft Agent fails to properly handle specially crafted .ACF files and may allow a remote attacker to execute arbitrary code.
I. DescriptionMicrosoft Agent is a software technology that enables an enriched form of user interaction that can make using and learning to use a computer easier and more natural.
A vulnerability exists in the way that Microsoft Agent handles specially crafted .ACF files. Exploitation can occur when a remote attacker convinces the user to visit a specially crafted web site.
Microsoft states that the following systems are affected:
- Microsoft Windows 2000 Service Pack 4
- Microsoft Windows XP Service Pack 2
- Microsoft Windows XP Professional x64 Edition
- Microsoft Windows Server 2003 and Microsoft Windows Server 2003 Service Pack 1
- Microsoft Windows Server 2003 for Itanium-based Systems and Microsoft Windows Server 2003 with SP1 for Itanium-based Systems
- Microsoft Windows Server 2003 x64 Edition
II. ImpactThis vulnerability may allow a remote attacker to execute arbitrary code with the privileges of the local user.
III. SolutionApply an update
Microsoft has released updates in Microsoft Security Bulletin MS06-068 to address this issue.
Workarounds
Microsoft has provided the following workarounds, please reference MS06-068 for further information.
- Temporarily prevent the Microsoft Agent ActiveX control from running in Internet Explorer
- Configure Internet Explorer to prompt before running ActiveX Controls or disable ActiveX Controls in the Internet and Local intranet security zone
- Set Internet and Local intranet security zone settings to “High” to prompt before running ActiveX Controls and Active Scripting in these zones
Systems Affected
References
http://www.microsoft.com/technet/security/bulletin/ms06-068.mspx
http://secunia.com/advisories/22878/
http://www.securityfocus.com/bid/21034
Credit
Thanks to Microsoft Security for reporting this vulnerability in Microsoft Security Bulletin MS06-068.
This document was written by Katie Steiner.
Other Information
| Date Public | 11/14/2006 |
| Date First Published | 11/14/2006 05:05:40 PM |
| Date Last Updated | 02/07/2007 |
| CERT Advisory | |
| CVE-ID(s) | CVE-2006-3445 |
| NVD-ID(s) | CVE-2006-3445 |
| US-CERT Technical Alerts | |
| Metric | 22.57 |
| Document Revision | 14 |
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|