Description

Multiple insecure method vulnerabilities exist in the iDefense COMRaider ActiveX control. The control exposes dangerous methods that can be invoked by malicious web pages, allowing arbitrary file operations and code execution.

Impact

A remote attacker can craft a malicious web page that invokes the insecure ActiveX methods, leading to arbitrary file creation, modification, or deletion on the victim's system. This can result in full system compromise.

Solution

Set the kill bit for the affected ActiveX control. Apply the vendor-supplied patch or update.

References