You are here

U-081: McAfee SaaS 'myCIOScn.dll' ActiveX Control Lets Remote Users Execute Arbitrary Code

January 13, 2012 - 9:15am

Addthis

PROBLEM:

McAfee SaaS 'myCIOScn.dll' ActiveX Control Lets Remote Users Execute Arbitrary Code

PLATFORM:

McAfee

ABSTRACT:

A remote user can create HTML that, when loaded by the target user, will execute arbitrary code on the target user's system.

reference  LINKS:

SecurityTracker Alert ID: 1026513
Zero Day Initiative ZDI-12-012
McAfee Threat Intelligence

IMPACT ASSESSMENT:

High

Discussion:

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of McAfee Security-as-a-Service. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

Impact:

The specific flaws exists within myCIOScn.dll. MyCioScan.Scan.ShowReport() will accept commands that are passed to a function that simply executes them without authentication. This can be leveraged by a malicious attacker to execute arbitrary code within the context of the browser.

Solution:

The killbit can be set on this control to disable scripting within Internet Explorer by modifying the data value of the Compatibilty Flags DWORD within the following location in the registry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\209EBDEE-065C-11D4-A6B8-00C04F0D38B7
If the Compatibility Flags value is set to 0x00000400 the control can no longer be instantiated inside the browser.

For more information, please see: How to stop an ActiveX control from running in Internet Explorer

 

Addthis