Umbra Wiki weakness weakness/CWE-623
Back to wiki

CWE-623 — Unsafe ActiveX Control Marked Safe For Scripting

provenance: imported · CWE: CWE-623

CWE-623: Unsafe ActiveX Control Marked Safe For Scripting

MITRE CWE weakness

Kind Weakness
Abstraction Variant
Status Draft
Likelihood of exploit

Description

An ActiveX control is intended for restricted use, but it has been marked as safe-for-scripting.

This might allow attackers to use dangerous functionality via a web page that accesses the control, which can lead to different resultant vulnerabilities, depending on the control's behavior.

Common consequences

  • Confidentiality, Integrity, Availability: Execute Unauthorized Code or Commands

Mitigations

Architecture and Design — During development, do not mark it as safe for scripting.

System Configuration — After distribution, you can set the kill bit for the control so that it is not accessible from Internet Explorer.

References

  • CWE page: https://cwe.mitre.org/data/definitions/623.html
  • CWE list: https://cwe.mitre.org/data/index.html