Awakening's Winds3D Viewer, which runs as a plugin within most popular web browsers, is vulnerable to a remotely exploitable arbitrary command execution vulnerability which can be triggered by making the user visit a malicious link/website.
Vulnerable Systems:
* Awingsoft Awakening Winds3D Viewer version 3.5.0.0 and prior
Workaround:
A possible mitigation action would be to enable MIME type filtering in your IDS/proxies and block Winds3D traffic: 'application/x-awingsoft-winds3d'. As a workaround, vulnerable users can also avoid this flaw by disabling the Winds3D Plugin in their web browsers:
*Mozilla Firefox*
~ . Go to the Tools menu, and select Options...
~ . Click on the Main tab
~ . Click on the Manage Add-ons...
~ . Disable Winds3D Plugin
Disclosure Timeline:
2009-05-19: Awingsoft notified of the vulnerability (no reply received)
2009-06-29: 2nd notice (no reply received)
2009-07-08: Published advisory CORE-2009-0519 as "User release".