1. Skip to navigation
  2. Skip to content
  3. Skip to secondary-content




MetaProducts MetaTreeX ActiveX Control Insecure Methods

Report ID: SA200900438
Source: Secunia
Date of Discovery: 20.01.2009
Criticality: Urgent
Affects:
MetaProducts MetaTreeX Control 1.x

Compromise From: From remote
Compromise Type: Manipulation of data
System access

Summary

Two vulnerabilities have been discovered in MetaProducts MetaTreeX Control, which can be exploited by malicious people to overwrite arbitrary files and compromise a user's system.

Detailed Description

1) The SaveToBMP.MetaTreeX ActiveX control (MTXControl.OCX) contains the insecure "SaveToBMP()" method. This can be exploited to corrupt arbitrary files in the context of the currently logged-on user.

2) The SaveToBMP.MetaTreeX ActiveX control (MTXControl.OCX) contains the insecure "SaveToFile()" method. This can be exploited to overwrite arbitrary files in the context of the currently logged-on user.

Successful exploitation of this vulnerability allows execution of arbitrary code.

The vulnerabilities are confirmed in MTXControl.OCX version 1.5.0.100. Other versions may also be affected.

Solution

Set the kill-bit for the affected ActiveX control.