CVE-2005-3650
Last modified
CVE-2005-3650 is a vulnerability of currently unknown severity. The CodeSupport.ocx ActiveX control, as used by Sony to uninstall the First4Internet XCP DRM, has "safe for scripting" enabled, which allows remote attackers to execute arbitrary code by calling vulnerable functions such as RebootMachine, IsAdministrator, and ExecuteCode.. EPSS estimates a 6.31% chance of exploitation in the next 30 days.
Description
The CodeSupport.ocx ActiveX control, as used by Sony to uninstall the First4Internet XCP DRM, has "safe for scripting" enabled, which allows remote attackers to execute arbitrary code by calling vulnerable functions such as RebootMachine, IsAdministrator, and ExecuteCode.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| First4internet Xcp Drm | First4internet Xcp Drm | All versions |
References
- http://secunia.com/advisories/17610Vendor Advisory
- http://www.kb.cert.org/vuls/id/312073Third Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2005/2454Vendor Advisory
- http://secunia.com/advisories/17610Vendor Advisory
- http://www.kb.cert.org/vuls/id/312073Third Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2005/2454Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-3650?
How severe is CVE-2005-3650?
How do I fix CVE-2005-3650?
Are you affected by CVE-2005-3650?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
