ICONICS WebHMI ActiveX Control Stack Buffer Overflow Vulnerability
BID:47704
Info
ICONICS WebHMI ActiveX Control Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 47704 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2011-2089 |
| Remote: | Yes |
| Local: | No |
| Published: | May 03 2011 12:00AM |
| Updated: | Apr 13 2015 09:01PM |
| Credit: | Scott Bell & Blair Strang |
| Vulnerable: |
Schneider-Electric PACiS SUI 1.1 RC7 Schneider-Electric PACiS SUI 1.1 RC6 Iconics WebHMI ActiveX Control 0 |
| Not Vulnerable: | |
Discussion
ICONICS WebHMI ActiveX Control Stack Buffer Overflow Vulnerability
The ICONICS WebHMI ActiveX control is prone to a remote stack-based buffer-overflow vulnerability that affects the 'GenVersion.dll' ActiveX control.
Attackers can exploit this issue to execute arbitrary code within the context of an application (typically Internet Explorer) that uses the ActiveX control. Failed exploit attempts will result in a denial-of-service condition.
The ICONICS WebHMI ActiveX control is prone to a remote stack-based buffer-overflow vulnerability that affects the 'GenVersion.dll' ActiveX control.
Attackers can exploit this issue to execute arbitrary code within the context of an application (typically Internet Explorer) that uses the ActiveX control. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
ICONICS WebHMI ActiveX Control Stack Buffer Overflow Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available:
Solution / Fix
ICONICS WebHMI ActiveX Control Stack Buffer Overflow Vulnerability
Solution:
Reportedly, the issue is fixed; however, Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly, the issue is fixed; however, Symantec has not confirmed this. Please contact the vendor for more information.
References
ICONICS WebHMI ActiveX Control Stack Buffer Overflow Vulnerability
References:
References:
- ICONICS WebHMI ActiveX Stack Overflow (Security-Assessment.com)
- SEVD 2013-344-01 Cybersecurity Vulnerability Disclosure (Schneider Electric)
- Vendor Homepage (ICONICS, Inc.)