CVE-2016-5228
Summary
| CVE | CVE-2016-5228 |
|---|---|
| State | PUBLISHED |
| Assigner | microfocus |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-07-03 01:59:09 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Stack-based buffer overflow in the PlayMacro function in ObjectXMacro.ObjectXMacro in WdMacCtl.ocx in Micro Focus Rumba 9.x before 9.3 HF 11997 and 9.4.x before 9.4 HF 12815 allows remote attackers to execute arbitrary code via a long MacroName argument. NOTE: some references mention CVE-2016-5226 but that is not a correct ID for any Rumba vulnerability. |
Risk And Classification
Primary CVSS: v3.0 9.8 CRITICAL from [email protected]
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Problem Types: CWE-119 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 9.8 | CRITICAL | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 10 | AV:N/AC:L/Au:N/C:C/I:C/A:C |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microfocus | Rumba | 9.4 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Micro Focus Rumba 9.x Security update - Rumba Knowledge Base - Rumba - Micro Focus Community | af854a3a-2127-422b-91ae-364da2661108 | community.microfocus.com | |
| Micro Focus Rumba+ v9.4 Multiple Stack Buffer Overflow Vulnerabilities - CXSecurity.com | af854a3a-2127-422b-91ae-364da2661108 | cxsecurity.com | |
| Micro Focus Rumba 9.3 - ActiveX Stack Buffer Overflow (PoC) - Windows dos Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| Zero Science Lab » Micro Focus Rumba+ v9.4 Multiple Stack Buffer Overflow Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.zeroscience.mk | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.