|Number of vulnerabilities||1|
|CVE ID|| CVE-2013-7246
|Public exploit||Public exploit code for vulnerability #1 is available.|
|Vulnerable software versions||
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The weakness exists due to buffer overflow in ActiveX component. A remote attacker can create a specially crafted Web page that passes an overly long argument to the insecure IconCreate method, trick the victim into opening it, trigger memory corruption and execute arbitrary code with privileges of the current user.
Successful exploitation of the vulnerability may result in arbitrary code execution on the vulnerable system.
Update to version 18.104.22.168 or later.External links