This host is installed with Fax Cover Page Editor and is prone to buffer overflow vulnerabilities. This NVT has been replaced by NVT secpod_ms11-024.nasl (OID:220.127.116.11.4.1.25618.104.22.1682408).
Successful exploitation will allow the attacker to cause a heap-based buffer overflow via a Fax Cover Page file containing specially crafted content. Impact Level: System/Application
No solution or patch was made available for at least one year since disclosure of this vulnerability. Likely none will be provided anymore. General solution options are to upgrade to a newer release, disable respective features, remove the product or replace the product by another one.
The flaw is due to an input validation error and a use-after-free error in the Fax Cover Page Editor 'fxscover.exe' when a function 'CDrawPoly::Serialize()' reads in data from a Fax Cover Page file ('.cov').
Fax Services Cover Page Editor 5.2 r2 on, Microsoft Windows XP Service Pack 3 and prior. Microsoft Windows 2K3 Service Pack 2 and prior. Micorsoft Windows 7
- Microsoft Windows Fax Cover Page Editor BOF Vulnerabilities
- Microsoft Windows DNS Memory Corruption Vulnerability - Mar09
- Microsoft Windows Server 2003 OpenType Font Engine DoS Vulnerability
- Microsoft Office Excel Axis and Art Object Parsing Remote Code Execution Vulnerabilities
- Microsoft Windows ActiveX Control Multiple Vulnerabilities (2562937)