The site-locking implementation in the SdcWebSecureBase interface in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance relies on a list of server domain names to restrict execution of ActiveX controls, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a DNS hijacking attack.
2010-05-12T11:46:31.750
2025-04-11T00:51:21.963
Deferred
CVSSv2: 9.3 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | consona | consona_dynamic_agent | - | Yes |
| Application | consona | consona_dynamic_agent | - | Yes |
| Application | consona | consona_dynamic_agent | - | Yes |
| Application | consona | consona_live_assistance | * | Yes |
| Application | consona | consona_subscriber_assistance | * | Yes |