Sploitus

Exploit for Microsoft Visual Studio 2005 WMI Object Broker vulnerability

saint · 2007-01-15

Exploit Code

MARKDOWN32 lines
## https://sploitus.com/exploit?id=SAINT:CE0E723D92F36418C7A3B000BE4BF5AC
Added: 01/15/2007  
CVE: [CVE-2006-4704](<https://vulners.com/cve/CVE-2006-4704>)  
BID: [20843](<http://www.securityfocus.com/bid/20843>)  
OSVDB: [30155](<http://www.osvdb.org/30155>)  


### Background

Microsoft [Visual Studio](<http://msdn.microsoft.com/vstudio/>) is a product to assist with software development in the Windows operating system. 

### Problem

A flaw in the WMI Object Broker ActiveX control allows attackers to bypass security zone restrictions, leading to command execution when a user opens a specially crafted web page. 

### Resolution

Apply the patch referenced in [Microsoft Security Bulletin 06-073](<http://www.microsoft.com/technet/security/bulletin/ms06-073.mspx>). 

### References

<http://www.microsoft.com/technet/security/bulletin/ms06-073.mspx>  
<http://www.zerodayinitiative.com/advisories/ZDI-06-047.html>  


### Limitations

Exploit works on Microsoft Visual Studio 2005 and requires a user to open the exploit in a web browser. 

### Platforms

Windows