CVE-2006-5198
WinZip FileView ActiveX Control Unsafe Method Exposure Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 before build 7245 allows remote attackers to execute arbitrary code via unspecified "unsafe methods."
El control ActiveX WZFILEVIEW.FileViewCtrl.61 (también conocido como control ActiveX Sky Software "FileView") para WinZip 10.0 anterior al build 7245 permite a atacantes remotos ejecutar código de su elección mediante "métodos no seguros" no especificados.
This vulnerability allows remote attackers to execute arbitrary code on systems with vulnerable installations of WinZip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page.
The specific flaw exists within the ActiveX control WZFILEVIEW.FileViewCtrl.61, CLSID:
A09AE68F-B14D-43ED-B713-BA413F034904
A re-branded version of the "FileView" ActiveX control developed by Sky Software. The object is marked "Safe for Scripting" and exposes several unsafe methods which can be leveraged to result in arbitrary code execution with no further interaction.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2006-10-09 CVE Reserved
- 2006-11-14 CVE Published
- 2010-04-30 First Exploit
- 2024-08-07 CVE Updated
- 2024-10-04 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://isc.sans.org/diary.php?storyid=1861 | X_refsource_misc | |
http://secunia.com/advisories/22891 | Third Party Advisory | |
http://securitytracker.com/id?1017226 | Vdb Entry | |
http://www.kb.cert.org/vuls/id/512804 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/451589/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/21060 | Vdb Entry | |
http://www.vupen.com/english/advisories/2006/4509 | Vdb Entry | |
http://www.winzip.com/wz7245.htm | X_refsource_confirm |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/16607 | 2010-04-30 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.zerodayinitiative.com/advisories/ZDI-06-040.html | 2018-10-17 | |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-067 | 2018-10-17 |