Vulnerability Detection in ActiveX Controls through Automated Fuzz Testing

SEI Report
In this 2008 paper, the authors explore results of a test of a large number of Active X controls, which provides insight into the current state of ActiveX security.
Publisher

Software Engineering Institute

Abstract

Vulnerabilities in ActiveX controls are frequently used by attackers to compromise systems using the Microsoft Internet Explorer web browser. A programming or design flaw in an ActiveX control can allow arbitrary code execution as the result of viewing a specially-crafted web page. In this paper, we examine effective techniques for fuzz testing ActiveX controls, using the Dranzer tool developed at CERT. By testing a large number of ActiveX controls, we are able to provide some insight into the current state of ActiveX security. 

Cite This SEI Report

Dormann, W., & Plakosh, D. (2008, January 1). Vulnerability Detection in ActiveX Controls through Automated Fuzz Testing. Retrieved September 22, 2026, from https://www.sei.cmu.edu/library/vulnerability-detection-in-activex-controls-through-automated-fuzz-testing/.

@techreport{dormann_2008,
author={Dormann, William and Plakosh, Daniel},
title={Vulnerability Detection in ActiveX Controls through Automated Fuzz Testing},
month={Jan},
year={2008},
institution={Software Engineering Institute, Carnegie Mellon University},
url={https://www.sei.cmu.edu/library/vulnerability-detection-in-activex-controls-through-automated-fuzz-testing/},
note={Accessed: 2026-Sep-22}
}

Dormann, William, and Daniel Plakosh. "Vulnerability Detection in ActiveX Controls through Automated Fuzz Testing." Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, January 1, 2008. https://www.sei.cmu.edu/library/vulnerability-detection-in-activex-controls-through-automated-fuzz-testing/.

W. Dormann, and D. Plakosh, "Vulnerability Detection in ActiveX Controls through Automated Fuzz Testing," Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, 1-Jan-2008 [Online]. Available: https://www.sei.cmu.edu/library/vulnerability-detection-in-activex-controls-through-automated-fuzz-testing/. [Accessed: 22-Sep-2026].

Dormann, William, and Daniel Plakosh. "Vulnerability Detection in ActiveX Controls through Automated Fuzz Testing." Software Engineering Institute, Carnegie Mellon University, Software Engineering Institute, 1 Jan. 2008. https://www.sei.cmu.edu/library/vulnerability-detection-in-activex-controls-through-automated-fuzz-testing/. Accessed 22 Sep. 2026.

Dormann, William; & Plakosh, Daniel. Vulnerability Detection in ActiveX Controls through Automated Fuzz Testing. Software Engineering Institute. 2008. https://www.sei.cmu.edu/library/vulnerability-detection-in-activex-controls-through-automated-fuzz-testing/