Yahoo! Assistant "ynotifier" ActiveX Control Code Execution Vulnerability
Last Update Date:
28 Jan 2011
Release Date:
14 May 2008
5245
Views
RISK: Medium Risk
A vulnerability has been identified in Yahoo! Assistant, which could be exploited by remote attackers to take complete control of an affected system. This issue is caused by a memory corruption error when instantiating the "ynotifier.dll" ActiveX control, which could be exploited by attackers to crash an affected browser or execute arbitrary code by tricking a user into visiting a specially crafted web page.
Impact
- Remote Code Execution
System / Technologies affected
- Yahoo! Assistant version 3.6 and prior
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Please contact the software manufacturer and upgrade to the latest version.
Vulnerability Identifier
Source
Related Link
Share with