Siemens SIMATIC Manager Step7 Project Folder DLL Loading Arbitrary Code Execution Vulnerability
BID:43533
Info
Siemens SIMATIC Manager Step7 Project Folder DLL Loading Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 43533 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 27 2010 12:00AM |
| Updated: | Sep 27 2010 12:00AM |
| Credit: | Symantec Security Response |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Siemens SIMATIC Manager Step7 Project Folder DLL Loading Arbitrary Code Execution Vulnerability
Siemens SIMATIC Manager is prone to a vulnerability that lets attackers execute arbitrary code.
An attacker can exploit this issue to execute arbitrary code by enticing an unsuspecting user into opening a malicious Step7 project.
SIMATIC Manager 5.3 and 5.4 SP4 are vulnerable; other versions may also be affected.
Siemens SIMATIC Manager is prone to a vulnerability that lets attackers execute arbitrary code.
An attacker can exploit this issue to execute arbitrary code by enticing an unsuspecting user into opening a malicious Step7 project.
SIMATIC Manager 5.3 and 5.4 SP4 are vulnerable; other versions may also be affected.
Exploit / POC
Siemens SIMATIC Manager Step7 Project Folder DLL Loading Arbitrary Code Execution Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user into opening a malicious Step7 project.
This issue is being exploited in the StuxNet virus to propagate.
To exploit this issue, an attacker must entice an unsuspecting user into opening a malicious Step7 project.
This issue is being exploited in the StuxNet virus to propagate.
Solution / Fix
Siemens SIMATIC Manager Step7 Project Folder DLL Loading Arbitrary Code Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Siemens SIMATIC Manager Step7 Project Folder DLL Loading Arbitrary Code Execution Vulnerability
References:
References:
- Siemens Homepage (Siemens)
- Stuxnet Infection of Step 7 Projects (Symantec)