TeamOn Import Object ActiveX control vulnerability
21 Apr. 2012
Summary
A vulnerability identified by the CERT Coordination Center (CERT/CC) exists in the TeamOn Import Object Microsoft ActiveX control used by BlackBerry Internet Service 2.0 on the BlackBerry Internet Service and the T-Mobile My E-mail web sites.
Vulnerable Systems:
* BlackBerry Internet Service 2.0
* Microsoft Internet Explorer
* T-Mobile My E-mail
When using Internet Explorer to view the BlackBerry Internet Service or T-Mobile My E-mail web sites that use the TeamOn Import Object ActiveX control, and when trying to install and run the ActiveX control, the ActiveX control introduces the vulnerability to the system.
The TeamOn Import Object ActiveX control has the following properties:
* Publisher: Research In Motion
* File name: TOImport.dll
* Class identifier: 1D95A7C7-3282-4DB7-9A48-7C39CE152A19
Vendor Status:
Blackberry had issued a security update for this vulnerability