CellCtrl Read & Write Excel ActiveX Control Buffer Overflow Vulnerability
BID:49752
Info
CellCtrl Read & Write Excel ActiveX Control Buffer Overflow Vulnerability
| Bugtraq ID: | 49752 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 23 2011 12:00AM |
| Updated: | Sep 23 2011 12:00AM |
| Credit: | Luigi Auriemma |
| Vulnerable: |
Sunway ForceControl 6.1 SP3 Sunway ForceControl 6.1 SP2 Sunway ForceControl 6.1 SP1 Cell Software Inc. CellCtrl 5.3.9.15 |
| Not Vulnerable: | |
Discussion
CellCtrl Read & Write Excel ActiveX Control Buffer Overflow Vulnerability
CellCtrl is prone to a buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data. This issue affects Read & Write Excel ActiveX control.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application (typically Internet Explorer) using the ActiveX control. Failed exploit attempts likely result in denial-of-service conditions.
CellCtrl 5.3.9.15 is vulnerable; other versions may also be affected.
CellCtrl is prone to a buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data. This issue affects Read & Write Excel ActiveX control.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application (typically Internet Explorer) using the ActiveX control. Failed exploit attempts likely result in denial-of-service conditions.
CellCtrl 5.3.9.15 is vulnerable; other versions may also be affected.
Exploit / POC
CellCtrl Read & Write Excel ActiveX Control Buffer Overflow Vulnerability
A proof-of-concept is available. Please see the reference for more details.
A proof-of-concept is available. Please see the reference for more details.
Solution / Fix
CellCtrl Read & Write Excel ActiveX Control Buffer Overflow Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
CellCtrl Read & Write Excel ActiveX Control Buffer Overflow Vulnerability
References:
References:
- CellCtrl Homepage (Cell Software Inc.)
- Microsoft Support Document 240797 (Microsoft)
- Sunway ForceControl Bugs (Luigi Auriemma)