PcVue ActiveX Control Multiple Security Vulnerabilities
BID:49795
Info
PcVue ActiveX Control Multiple Security Vulnerabilities
| Bugtraq ID: | 49795 |
| Class: | Unknown |
| CVE: |
CVE-2011-4042 CVE-2011-4043 CVE-2011-4044 CVE-2011-4045 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 27 2011 12:00AM |
| Updated: | Dec 06 2011 10:07PM |
| Credit: | Luigi Auriemma |
| Vulnerable: |
ARC Informatique PlantVue 0 ARC Informatique PCVue 6 ARC Informatique PCVue 10.0 ARC Informatique FrontVue 0 |
| Not Vulnerable: | |
Discussion
PcVue ActiveX Control Multiple Security Vulnerabilities
The PcVue ActiveX control is prone to multiple vulnerabilities.
Successfully exploiting these issues allows remote attackers to create or overwrite arbitrary local files and execute arbitrary code. Failed exploit attempts may result in a denial-of-service condition.
PcVue 10.0 is vulnerable; other versions may also be affected.
The PcVue ActiveX control is prone to multiple vulnerabilities.
Successfully exploiting these issues allows remote attackers to create or overwrite arbitrary local files and execute arbitrary code. Failed exploit attempts may result in a denial-of-service condition.
PcVue 10.0 is vulnerable; other versions may also be affected.
Exploit / POC
PcVue ActiveX Control Multiple Security Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting user to view a malicious Web page.
The following exploits and proof of concepts are available:
To exploit these issues, an attacker must entice an unsuspecting user to view a malicious Web page.
The following exploits and proof of concepts are available:
Solution / Fix
PcVue ActiveX Control Multiple Security Vulnerabilities
Solution:
Vendor updates are available. Please contact the vendor for more information.
Solution:
Vendor updates are available. Please contact the vendor for more information.