HomeCommunitySecurity Blog

Security Blog

 

Threat Lab Report: Troj.Downloader.JS.Agent.edg

Posted By Netgear Threat Lab at 5:28 PM, October 26, 2009

Description of Report (Troj.Downloader.JS.Agent.edg):

The Office OCX Word Viewer OCX ActiveX control with the CLSID:97AF4A45-49BE-4485-9F55-91AB40F288F2 is prone to a remote code-execution vulnerability. The vulnerability is caused due to the use of the insecure OpenWebFile() method. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to download arbitrary executable files to the victim's system and execute arbitrary code on the system with the privileges of the victim.

Affected Version: Office OCX Word Viewer OCX 3.2

Posted by: Netgear Threat Lab at 5:28 PM
Categories: Malware , Netgear Threat Lab , Viruses

No TrackBacks

TrackBack URL: http://prosecure.netgear.com/cgi-bin/mt/mt-tb.cgi/50

Comments