Threat Monitor
Trojan.JS.Agent.ajg
| Aliase: | |
|---|---|
| Pattern: | 200907091330 |
| Threat Typ | Verbreitung | Betroffene Systeme | Gefährlichkeit |
|---|---|---|---|
|
|
|
The Microsoft Video Controller ActiveX Library for streaming video (msvidctl.dll) with the CLSID:0955AC62-BF2E-4CBA-A2B9-A63F772D46CF is proned to a buffer overflow vulnerability caused due to a boundary error.The ActiveX controls provided by msvidctl.dll fail to properly handle file input, which can result in a stack-based buffer overflow via specially crafted image content. This can allow the Structured Exception Handler (SEH) to be overwritten, that would allow the attacker to execute arbitrary code on the target system with the privileges of the victim.
The sample is from http://***.3322.org/aa/index.htm.
The code of index.html is : src='go.jpg'.
Here's a screenshot of the index.html code:

Here's a screenshot of the go.jpg code:

Affected Versions:
Microsoft, Windows 2003 Server SP2 x64
Microsoft, Windows 2003 Server SP2 Itanium
Microsoft, Windows 2003 Server SP2
Microsoft, Windows XP SP2
Microsoft, Windows XP SP2 Professional x64
Microsoft, Windows XP SP3


