Avaya Media Application Server Client Remote Code Execution Vulnerability
BID:48956
Info
Avaya Media Application Server Client Remote Code Execution Vulnerability
| Bugtraq ID: | 48956 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 02 2011 12:00AM |
| Updated: | Aug 17 2011 07:10AM |
| Credit: | Zero Day Initiative |
| Vulnerable: |
Avaya Media Application Server 0 Avaya Aura Application Server 5300 SIP Core 2.0 Avaya Aura Application Server 5300 SIP Core 1.0 |
| Not Vulnerable: | |
Discussion
Avaya Media Application Server Client Remote Code Execution Vulnerability
Avaya Media Application Server is prone to a remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code with SYSTEM-level privileges. Successfully exploiting this issue will completely compromise the affected computer.
Avaya Media Application Server is prone to a remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code with SYSTEM-level privileges. Successfully exploiting this issue will completely compromise the affected computer.
Exploit / POC
Avaya Media Application Server Client Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Avaya Media Application Server Client Remote Code Execution Vulnerability
Solution:
The vendor has released an advisory and fixes. Please see the references for details.
Solution:
The vendor has released an advisory and fixes. Please see the references for details.
References
Avaya Media Application Server Client Remote Code Execution Vulnerability
References:
References:
- ASA-2011-213 Media Application Server Remote Code Execution Vulnerability (Avaya)
- Avaya Homepage (Avaya Inc.)
- Nortel Media Application Server cstore.exe cs_anams Remote Code Execution Vulner (Zero Day Initiative)