RULE(RULE ID:332938)

Rule General Information
Release Date: 2021-03-26
Rule Name: Microsoft Rich Textbox Control SaveFile Insecure Method Arbitrary File Overwrite Vulnerability (CVE-2008-0237)
Severity:
CVE ID:
Rule Protection Details
Description: There exists a file overwriting vulnerability in Microsoft Rich Textbox Control ActiveX control. The flaw is due to lack of path verification in the control's method SaveFile. A remote attacker may exploit this vulnerability via a specially crafted web page to create or modify arbitrary files on the target system. After successfully exploiting this vulnerability, a file on the target file system might be created, or overwritten. An attacker may write a file to the start up folder in order to execute arbitrary code during the next reboot or logon session or overwrite credential files on the system in order to gain access to the system. Thus, the behaviour of the target depends on the intention of the attacker.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference: SecurityFocusBID:27201
ExploitDB:4874
http://shinnai.altervista.org/exploits/txt/TXT_DZVN8CwCha0I2fI3NeEs.html
https://exchange.xforce.ibmcloud.com/vulnerabilities/39557
Solutions
There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.