Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Update Protection against Symantec AppStream Client LaunchObj ActiveX Control Program Execution

Subscribe

Check Point Reference: CPAI-2009-023
Date Published:
Severity:
Source: Secunia Advisory: SA33582
Industry Reference(s): CVE-2008-4388
Protection Provided by: IPS-1
  • IPS-1
  • IPS-1 NGX R65
Who is Vulnerable?
Symantec AppStream Client 5.x
Vulnerability Description
A remote code execution vulnerability was reported in Symantec AppStream Client. The AppStream Client is part of a Software Virtualization Solution (SVS) which allows streaming of virtual applications to users in an enterprise environment using the AppStream Server. The vulnerability is due to failure to properly validate whether the server to which the client connects is valid and authorized or not. Remote unauthenticated attackers can exploit this vulnerability by masquerading as a valid server and convincing a client to open a crafted HTML file. Successful exploitation will lead to arbitrary files being downloaded and executed within the context of the client.
Vulnerability Details
The vulnerability exists in the LaunchObj ActiveX Control. This vulnerability is due to a design weakness as a result of which any webserver can masquerade as a legitimate AppStream server and serve the AWEClientSetup.exe. An attacker can expolit this by enticing a target user to visit a malicious web page. Successful exploitation allows execution of arbitrary code.

Protection Overview
By enabling this protection, IPS-1 will detect and block attempts to access the ActiveX LaunchObj controls for Symantec AppStream Client.

To configure the defense, select your product from the list below and follow the related protection steps.

IPS-1 & IPS-1 NGX R65

How Can I Protect My Network?
1. In the IPS-1 Policy Manager, click on the Protection tab.
2. In the Protection tree, click Application Intelligence > Badfiles, and select the ActiveX Parser protection group.
3. Click User defined bad ActiveX Class ID (IPS-1 NGX R65 only).
4. In the configuration pane, under Settings, check Active.
5. Click on Install Policy.

How Do I Know if My Network is Under Attack?
Upon attack, the following entries will be logged:

 Alert Name: Badfiles ActiveX class in HTML file Alert/Filter
 Description: User defined bad ActiveX Class ID