CWE-623: Unsafe ActiveX Control Marked Safe For Scripting
Unsafe ActiveX Control Marked Safe For Scripting
Weakness ID: 623 (Weakness Variant)
Status: Draft
Description
Description Summary
An ActiveX control is intended for restricted use, but it has been marked as safe-for-scripting.
Extended Description
This might allow attackers to use dangerous functionality via a web page that accesses the control, which can lead to different resultant vulnerabilities, depending on the control's behavior.
Time of Introduction
Architecture and Design
Implementation
Common Consequences
Scope
Effect
Confidentiality
Integrity
Availability
Technical Impact: Execute unauthorized code or
commands
[REF-11] M. Howard and
D. LeBlanc. "Writing Secure Code". Chapter 16, "What ActiveX Components Are Safe for
Initialization and Safe for Scripting?" Page 510. 2nd Edition. Microsoft. 2002.
[REF-7] Mark Dowd, John McDonald
and Justin Schuh. "The Art of Software Security Assessment". Chapter 12, "ActiveX Security", Page 749.. 1st Edition. Addison Wesley. 2006.