|
Microsoft Visual Studio User Control Load Event Vulnerability
|
|
Secunia Advisory:
|
SA18409
|
|
|
Release Date:
|
2006-01-11
|
|
Last Update:
|
2006-08-04
|
|
Popularity:
|
16,880 views
|
|
|
Critical:
|
 Less critical
|
|
Impact:
|
System access
|
|
Where:
|
From remote
|
|
Solution Status:
|
Unpatched
|
|
| Software: | Microsoft Visual C++ 6.x Microsoft Visual Studio .NET 2002 Microsoft Visual Studio .NET 2003 Microsoft Visual Studio 2005 Microsoft Visual Studio 6 Enterprise Microsoft Visual Studio 6 Professional
|
|
|
Secunia CVSS-2 Score:
|
Available in Secunia business solutions
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| Advisory Content (Page 1 of 3) | [ 1 ] [ 2 ] [ 3 ] | |
|
Description: priestmaster has discovered a vulnerability in Microsoft Visual Studio, which can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to a design error that allows program code within the "Load" event of a user-defined control to be automatically executed when a project containing a form that uses the malicious control is opened. This can be exploited to execute arbitrary program code.
Successful exploitation requires that the user is e.g. tricked into opening a Solution file in a malicious Visual Studio project.
The vulnerability has been confirmed in Microsoft Visual C# 2005 Express Edition. Other versions may also be affected.
Note: It has also possible to modify Visual Studio's ".dsp" project files to include arbitrary post-build commands that are executed when the project is built.
Change Page: [ 1 ] [ 2 ] [ 3 ]
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|