1. Skip to navigation
  2. Skip to content
  3. Skip to secondary-content




SmartVMD ActiveX Control Multiple Insecure Methods

Report ID: SA200900478
Source: Secunia
Date of Discovery: 22.01.2009
Criticality: Low
Affects:
SmartVMD ActiveX Control 1.x

Compromise From: From remote
Compromise Type: Manipulation of data

Summary

Two vulnerabilities have been discovered in SmartVMD ActiveX Control, which can be exploited by malicious people to overwrite and delete arbitrary files.

Detailed Description

The vulnerabilities are caused due to the VideoMovementDetection.MotionDetection (VideoMovementDetection.dll) ActiveX control providing the insecure "StartVideoSaving()" and "SaveMaskToFile()" methods. This can be exploited to delete or overwrite arbitrary files on the local system via arguments passed to the affected methods.

These vulnerabilities are confirmed in version 1.1 trial (VideoMovementDetection.dll version 1.0.0.1). Other versions may also be affected.

Solution

Set the kill-bit for the affected ActiveX control.