PT-2010-1407 · Awingsoft · Winds3D Viewer+3

·

CVE-2009-4588

·

Published

2010-01-07

·

Updated

2024-02-14

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions AwingSoft Awakening Web3D Player and Winds3D Viewer versions 3.5.0.0 Beta, 3.0.0.5, and earlier
Description The issue is related to a heap-based buffer overflow in the WindsPlayerIE.View.1 ActiveX control in WindsPly.ocx. This can be triggered by a long SceneUrl property value, potentially allowing remote attackers to cause a denial of service or execute arbitrary code.
Recommendations For versions 3.5.0.0 Beta, 3.0.0.5, and earlier, consider disabling the WindsPlayerIE.View.1 ActiveX control until a patch is available to prevent potential exploitation. Restrict access to the SceneUrl property to minimize the risk of arbitrary code execution.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-4588

Affected Products

Awingsoft Awakening Web3D Player
Winds3D Viewer
Windsplayerie.View.1 Activex Control
Windsply.Ocx