ActiveX Control Vulnerability in Microsoft Internet Information Services
CVE-2008-4300

Currently unrated

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
29 September 2008

Summary

An ActiveX control flaw in the adsiis.dll component of Microsoft Internet Information Services (IIS) can be exploited by remote attackers. By sending a specially crafted long string as the second argument to the GetObject method, attackers can trigger a denial of service condition, resulting in a crash of the browser. This vulnerability poses a significant risk to users of IIS, as it can be exploited without requiring physical access to the vulnerable system.

References

EPSS Score

14% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.