Quest InTrust Annotation Objects ActiveX Control Index out of Bounds

Strike ID:
E12-7js01
CVSS:
10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C)
False Positive:
f
Variants:
5
Year:
2012

Description

This strike exploits a memory access vulnerability in Quest InTrust. The vulnerability is due to a flawed ActiveX control, which allows a user to specify a function pointer. A remote, unauthenticated attacker could exploit this vulnerability by enticing a user to view a specially crafted web page.

CVE

Bid