Invensys Wonderware inBatch BatchField ActiveX Control Stack Buffer Overflow Vulnerability
BID:47385
Info
Invensys Wonderware inBatch BatchField ActiveX Control Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 47385 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 15 2011 12:00AM |
| Updated: | Apr 15 2011 12:00AM |
| Credit: | Jeremy Brown |
| Vulnerable: |
Invensys Wonderware InBatch 9.0 SP1 Invensys Wonderware InBatch 9.0 Invensys Wonderware InBatch 8.1 SP1 Invensys Wonderware InBatch 8.1 |
| Not Vulnerable: | |
Discussion
Invensys Wonderware inBatch BatchField ActiveX Control Stack Buffer Overflow Vulnerability
Invensys Wonderware inBatch is prone to a remote stack-based buffer-overflow vulnerability that affects the inBatch BatchField ActiveX control.
Attackers can exploit this issue to execute arbitrary code within the context of an application (typically Internet Explorer) that uses the ActiveX control. Failed exploit attempts will result in a denial-of-service condition.
Invensys Wonderware inBatch 8.1 and 9.0 SP1 is vulnerable; other versions may also be affected.
Invensys Wonderware inBatch is prone to a remote stack-based buffer-overflow vulnerability that affects the inBatch BatchField ActiveX control.
Attackers can exploit this issue to execute arbitrary code within the context of an application (typically Internet Explorer) that uses the ActiveX control. Failed exploit attempts will result in a denial-of-service condition.
Invensys Wonderware inBatch 8.1 and 9.0 SP1 is vulnerable; other versions may also be affected.
Exploit / POC
Invensys Wonderware inBatch BatchField ActiveX Control Stack Buffer Overflow Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Invensys Wonderware inBatch BatchField ActiveX Control Stack Buffer Overflow Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for details.
Solution:
The vendor released an update to address this issue. Please see the references for details.
References
Invensys Wonderware inBatch BatchField ActiveX Control Stack Buffer Overflow Vulnerability
References:
References: