Siemens Solid Edge WebPartHelper ActiveX Remote Code Execution Vulnerability
BID:60158
Info
Siemens Solid Edge WebPartHelper ActiveX Remote Code Execution Vulnerability
| Bugtraq ID: | 60158 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 26 2013 12:00AM |
| Updated: | May 26 2013 12:00AM |
| Credit: | rgod |
| Vulnerable: |
Siemens Solid Edge 0 |
| Not Vulnerable: | |
Discussion
Siemens Solid Edge WebPartHelper ActiveX Remote Code Execution Vulnerability
Siemens Solid Edge WebPartHelper ActiveX control is prone to a remote code-execution vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application (typically Internet Explorer) using the ActiveX control. Failed exploit attempts will likely result in denial-of-service conditions.
Siemens Solid Edge WebPartHelper ActiveX control is prone to a remote code-execution vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application (typically Internet Explorer) using the ActiveX control. Failed exploit attempts will likely result in denial-of-service conditions.
Exploit / POC
Siemens Solid Edge WebPartHelper ActiveX Remote Code Execution Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
Siemens Solid Edge WebPartHelper ActiveX Remote Code Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Siemens Solid Edge WebPartHelper ActiveX Remote Code Execution Vulnerability
References:
References:
- Siemens Homepage (Siemens)
- Siemens Solid Edge Homepage (Siemens)