Skip to main content

Microsoft WMI Administrative Tools Trusted Value Remote Code Execution Vulnerability

Last Update Date: 28 Jan 2011 Release Date: 23 Dec 2010 5186 Views

RISK: Medium Risk

A vulnerability has been identified in Microsoft WMI Administrative Tools, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a memory trust error in the "WBEMSingleView.ocx" ActiveX control when using the parameter supplied via the "AddContextRef()" method as a pointer, which could allow attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.


Impact

  • Remote Code Execution

System / Technologies affected

  • Microsoft WMI Administrative Tools version 1.1 and prior

Solutions

There is no patch available for this vulnerability currently.


Vulnerability Identifier

  • No CVE information is available

Source


Related Link