IncrediMail.IMMenuShellExt.ActiveX.Control.Command.Execution

description-logoDescription

There is a stack based buffer overflow vulnerability in the DoWebMenuAction function, in the IncrediMail IMMenuShellExt ActiveX control (ImShExt.dll),
which may allow remote attackers to execute arbitrary code.

affected-products-logoAffected Products

IncrediMail 2.x
IncrediMail 3.x
IncrediMail 5.x

Impact logoImpact

System compromise, remote code execution.

recomended-action-logoRecommended Actions

Set the kill bit for the affected ActiveX control.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)