in

eEye Digital Security

The endpoint to vulnerability starts here.

 

Remedy for vulnerability items, “Microsoft Visual Basic 6.0 ActiveX Runtimes Code Execution (932349)”?

Last post 10-18-2009 1:06 PM by pdltoys. 23 replies.
Page 2 of 2 (24 items) < Previous 1 2
Sort Posts: Previous Next
  • 05-08-2009 9:53 AM In reply to

    • reedpb
    • Top 500 Contributor
    • Joined on 05-08-2009
    • Posts 2

    Re: Remedy for vulnerability items, “Microsoft Visual Basic 6.0 ActiveX Runtimes Code Execution (932349)”?

     After doing the above...  error,

    "The installation package could not be opened.  Verify that the package exists and that you can access it, or contact the application vendor to verify that this is a valid Windows Installer package." 

    My problem is the Comct232.ocx file needs to be updated from 6.0.80.22.  

    I created a vb-file in the C:drive and tried to extract it using the C: prompt command to that folder and it wont work. 

  • 06-11-2009 7:34 AM In reply to

    • sp00led
    • Top 500 Contributor
    • Joined on 06-10-2009
    • Alabama
    • Posts 3

    Re: Remedy for vulnerability items, “Microsoft Visual Basic 6.0 ActiveX Runtimes Code Execution (932349)”?

    Make sure you include the file name .msi in the source of the command. I got the same problem you did but once I added that it found the .msi file and extracted it.

    - Information Assurance pays the bills!
  • 08-05-2009 8:24 AM In reply to

    • reedpb
    • Top 500 Contributor
    • Joined on 05-08-2009
    • Posts 2

    Re: Remedy for vulnerability items, “Microsoft Visual Basic 6.0 ActiveX Runtimes Code Execution (932349)”?

     Sorry for the late response, but thanks for the help.

  • 08-12-2009 5:52 AM In reply to

    Re: Remedy for vulnerability items, “Microsoft Visual Basic 6.0 ActiveX Runtimes Code Execution (932349)”?

     I have the same issue....have seen it on three separate scans this week. Am wondering if manually extracting the files from the Microsoft update and then replacing the old .ocx files would break anything.

    E-RPM SOFT COM
    336-793-0285
  • 08-12-2009 8:34 AM In reply to

    • bpatten
    • Top 10 Contributor
    • Joined on 09-24-2007
    • Irvine, CA
    • Posts 125

    Re: Remedy for vulnerability items, “Microsoft Visual Basic 6.0 ActiveX Runtimes Code Execution (932349)”?

    That is certainly an option to remediate the vulnerability. The problem is that the MS patch, only patches MS products, not 3rd party products that use the VB6 code. Its up to the 3rd party vendor to patch their software and your machine otherwise. You can extract and replace on your machine, and cross your fingers that it doesnt break whatever 3rd party app you're using, or contact the 3rd party application developer.

    Hope that helps.

     

  • 08-13-2009 3:50 AM In reply to

    Re: Remedy for vulnerability items, “Microsoft Visual Basic 6.0 ActiveX Runtimes Code Execution (932349)”?

    bpatten:
    The problem is that the MS patch, only patches MS products, not 3rd party products that use the VB6 code.
     

    Brian,

         I have an off the wall idea.  Would it be possible for the Retina team (as a future update change to Retina) to make Retina provide you a path to where it is finding the vulnerability?  Maybe something similar to the "Applications Arguments" line that was recently added into Blink's Kevlar module alerts (see example below):

    Event ID: BLINK-APP-100
    Severity: High
    Description: Blink detected a suspicious system call.
    Alert: Yes
    Application: C:\Program Files (x86)\Windows Media Player\wmplayer.exe
    Reason: KERNEL32.DLL!GetModuleHandleA
    Action: Terminate Process
    Application Arguments: "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:1

    ---------------------------------------------------------------------------------------------------------------------------

    In the case of Retina it would be helpful to see something like this:

    Example:  

    Target Location - C:\Windows\System32\accsp.dll  (version)

    - If the vulnerability existed in the accsp.dll file of Windows and Retina is looking at its version number.

    I don't know really, but something pointing you to the issue itself would be helpful.

  • 08-13-2009 9:12 AM In reply to

    • bpatten
    • Top 10 Contributor
    • Joined on 09-24-2007
    • Irvine, CA
    • Posts 125

    Re: Remedy for vulnerability items, “Microsoft Visual Basic 6.0 ActiveX Runtimes Code Execution (932349)”?

    I'll see if thats something we can add.

  • 08-13-2009 9:28 AM In reply to

    Re: Remedy for vulnerability items, “Microsoft Visual Basic 6.0 ActiveX Runtimes Code Execution (932349)”?

    bpatten:
    I'll see if thats something we can add

    Awesome, I see the ticket you created for me:

    Communication History
    On 8/13/2009 9:15:36 AM eEye Digital Security wrote:

    Customer would like to request the addition of the audit ID and confirmation details, so that end users can see what file/regkey we're reviewing determine that its vulnerable.


    On 8/13/2009 9:16:23 AM eEye Digital Security wrote:

    Hi Jeff,
    Forwarding to product management for future consideration to the VA report.
    Thanks,
    Brian

     

    Thank you.

  • 10-18-2009 1:06 PM In reply to

    Re: Remedy for vulnerability items, “Microsoft Visual Basic 6.0 ActiveX Runtimes Code Execution (932349)”?

     

    Make sure you include the file name .msi in the source of the command. I got the same problem you did but once I added that it found the .msi file and extracted it.

    www.pdltoys.com
    623-239-1807
Page 2 of 2 (24 items) < Previous 1 2
© 1995 - 2009 eEye Incorporated