RULE(RULE ID:310999)

Rule General Information
Release Date: 2018-08-06
Rule Name: Attachmate Reflection FTP Client Activex Getglobalsettings Memory Corruption Vulnerability (CVE-2014-0603)
Severity:
CVE ID:
Rule Protection Details
Description: The rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to cause a denial of service (memory corruption) and execute arbitrary code via vectors related to the (1) GetGlobalSettings or (2) GetSiteProperties3 methods, which triggers a dereference of an arbitrary memory address.
Impact: An attacker can execute arbitrary code in the context of the vulnerable system. Failed exploit may cause denial-of-service attack.
Affected OS: Windows
Reference: http://support.attachmate.com/techdocs/2501.html
ZeroDayInitiative:ZDI-14-288
ZeroDayInitiative:ZDI-14-291
Solutions
More advisories have been published on the website, please visit for more suggestions:
http://support.microsoft.com/kb/240797
http://support.attachmate.com/techdocs/2546.html