Microsoft Commerce Server contains a flaw that may allow a malicious user to run commands of their choice via the OWC Package installer. The issue is triggered when the attacker has log on credential to the computer and access to the directory of the OWC package. It is possible that the flaw may allow running a program of the attacker's choice resulting in a loss of confidentiality, integrity, and/or availability.
Classification
Location:
Local Access Required,
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity,
Loss of Availability
Exploit:
Exploit Unknown
Disclosure:
OSVDB Verified
Solution
Currently, there are no known workarounds or upgrades to correct this issue. However, Microsoft has released a patch to address this vulnerability.