ActiveX Repurposing.. (aka: Other bugs your static analyzer will never find..) (aka 0day^H^H 485day bug!)
ID: 1253b7dd-45e9-5476-a2de-a8af2a72258a
STIX ID: report--1253b7dd-45e9-5476-a2de-a8af2a72258a
Feed Name: SensePost Blog
The report describes a Juniper SSL‑VPN ActiveX control flaw where the control's self-upgrade and configuration handling can be abused by a malicious webpage: an unsigned upgrade file is downloaded to a predictable path (C:\predictable_location) and a crafted INI file can include an UninstallString with arbitrary commands. By instantiating the control with the malicious INI, an attacker can trigger the uninstall method to execute arbitrary code on the victim's machine, demonstrating a reliable client-side remote code execution vector and highlighting limitations of static analysis tools.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
