Detailed Description
1) The SaveToBMP.MetaTreeX ActiveX control (MTXControl.OCX) contains the insecure "SaveToBMP()" method. This can be exploited to corrupt arbitrary files in the context of the currently logged-on user.
2) The SaveToBMP.MetaTreeX ActiveX control (MTXControl.OCX) contains the insecure "SaveToFile()" method. This can be exploited to overwrite arbitrary files in the context of the currently logged-on user.
Successful exploitation of this vulnerability allows execution of arbitrary code.
The vulnerabilities are confirmed in MTXControl.OCX version 1.5.0.100. Other versions may also be affected.