Vulnerable Systems:
* PSFormX ActiveX control with CLSID {56393399-041A-4650-94C7-13DFCB1F4665}
* WebScan ActiveX control with CLSID {7B297BFD-85E4-4092-B2AF-16A91B2EA103}
CA Technologies support is alerting users to multiple security risks with the PSFormX and WebScan ActiveX controls previously available from the CA Global Security Advisor site. Multiple vulnerabilities exist that can potentially allow a remote attacker to execute arbitrary code. The vulnerabilities, CVE-2010-2193, are due to insufficient verification of input parameters. CA has issued a single replacement ActiveX control for both affected controls in May of 2009. These controls are not included in any CA product.
Workaround:
The PSFormX and WebScan ActiveX controls were retired from the CA Global Security Advisor site in May of 2009. To disable the PSFormX and WebScan controls from running, set the kill bit for the controls in the registry. Note: review Microsoft KB article 240797 prior updating the registry.
PSFormX ActiveX control
Create a DWORD with the name of "Compatibility Flags" containing the value 0x00000400 in the following registry key. If the key does not exist, create it under the following location:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{56393399-041A-4650-94C7-13DFCB1F4665}]
WebScan ActiveX control
Create a DWORD with the name of "Compatibility Flags" containing the value 0x00000400 in the following registry key. If the key does not exist, create it under the following location:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{7B297BFD-85E4-4092-B2AF-16A91B2EA103}]