Mitsubishi MC-WorX 'IcoLaunch.dll'' ActiveX Control Remote Code Execution Vulnerability
BID:62414
Info
Mitsubishi MC-WorX 'IcoLaunch.dll'' ActiveX Control Remote Code Execution Vulnerability
| Bugtraq ID: | 62414 |
| Class: | Unknown |
| CVE: |
CVE-2013-2817 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 15 2013 12:00AM |
| Updated: | Feb 25 2014 07:51AM |
| Credit: | Blake |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Mitsubishi MC-WorX 'IcoLaunch.dll'' ActiveX Control Remote Code Execution Vulnerability
Mitsubishi MC-WorX is prone to a remote code-execution vulnerability.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application (typically Internet Explorer) using the ActiveX control. Failed exploit attempts will likely result in denial-of-service conditions.
Mitsubishi MC-WorX 8.02 is vulnerable; other versions may also be affected.
Mitsubishi MC-WorX is prone to a remote code-execution vulnerability.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application (typically Internet Explorer) using the ActiveX control. Failed exploit attempts will likely result in denial-of-service conditions.
Mitsubishi MC-WorX 8.02 is vulnerable; other versions may also be affected.
Exploit / POC
Mitsubishi MC-WorX 'IcoLaunch.dll'' ActiveX Control Remote Code Execution Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
Mitsubishi MC-WorX 'IcoLaunch.dll'' ActiveX Control Remote Code Execution Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Mitsubishi MC-WorX 'IcoLaunch.dll'' ActiveX Control Remote Code Execution Vulnerability
References:
References: