Autodesk.LiveUpdate.ActiveX.Control.Access

description-logoDescription

This indicates an attack attempt against a remote code execution vulnerability in Autodesk LiveUpdate ActiveX Control shipped with multiple products.
The vulnerability is caused by an error when the vulnerable software handles a specially crafted parameter passed to the ApplyPatch() method. It allows a remote attacker to execute arbitrary code.

affected-products-logoAffected Products

Autodesk Design Review 2009
Autodesk Revit Architecture 2009

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

We are not aware of any update or patch for this vulnerability as of this writing.
Refer to this guideline on how to set the kill bit for the affected ActiveX Control (CLSID:89EC7921-729B-4116-A819-DF86A4A5776B):
http://support.microsoft.com/kb/240797

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)