Advantech Studio ISSymbol ActiveX Control Multiple Buffer Overflow Vulnerabilities
BID:47596
Info
Advantech Studio ISSymbol ActiveX Control Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 47596 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2011-0340 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 27 2011 12:00AM |
| Updated: | Apr 02 2013 03:57PM |
| Credit: | Dmitriy Pletnev |
| Vulnerable: |
Indusoft Web Studio 7.0B2 Indusoft Thin Client 7.0 Advantech Advantech Studio 6.1 SP6 Build 61.6.0 |
| Not Vulnerable: |
Indusoft Web Studio 7.0.1 04 Advantech Advantech Studio 7.0 |
Discussion
Advantech Studio ISSymbol ActiveX Control Multiple Buffer Overflow Vulnerabilities
The Advantech Studio ISSymbol ActiveX control is prone to multiple buffer-overflow vulnerabilities because the application fails to perform adequate boundary checks on user-supplied input.
Attackers may exploit these issues to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts will likely result in denial-of-service conditions.
Advantech Studio 6.1 SP6 Build 61.6.01.05 is vulnerable; other versions may also be affected.
The Advantech Studio ISSymbol ActiveX control is prone to multiple buffer-overflow vulnerabilities because the application fails to perform adequate boundary checks on user-supplied input.
Attackers may exploit these issues to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts will likely result in denial-of-service conditions.
Advantech Studio 6.1 SP6 Build 61.6.01.05 is vulnerable; other versions may also be affected.
Exploit / POC
Advantech Studio ISSymbol ActiveX Control Multiple Buffer Overflow Vulnerabilities
A commercial exploit is available through the GLEG Agora SCADA+ exploit pack. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit is available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
A commercial exploit is available through the GLEG Agora SCADA+ exploit pack. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit is available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Advantech Studio ISSymbol ActiveX Control Multiple Buffer Overflow Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Advantech Studio ISSymbol ActiveX Control Multiple Buffer Overflow Vulnerabilities
References:
References:
- Advantech Studio Homepage (Advantech)
- Indusoft Security Update (Indusoft)
- InduSoft Web Studio Homepage (Indusoft)
- ICS-CERT ALERT "ICS-ALERT-11-230-01 - AGORA SCADA+ Update 1.4" (ICS-CERT)
- ICSA-12-137-02�??ADVANTECH STUDIO ISSYMBOL ACTIVEX BUFFER OVERFLOWS (ICS-CERT)
- Secunia Research: Advantech Studio ISSymbol ActiveX Control Buffer Overflow Vuln (Secunia)