NetIQ Security Manager 'NQMcsVarSet' ActiveX Remote Code Execution Vulnerability
BID:68440
Info
NetIQ Security Manager 'NQMcsVarSet' ActiveX Remote Code Execution Vulnerability
| Bugtraq ID: | 68440 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2014-0602 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 08 2014 12:00AM |
| Updated: | Jul 08 2014 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
NetIQ Security Manager 'NQMcsVarSet' ActiveX Remote Code Execution Vulnerability
NetIQ Security Manager is prone to a remote code-execution vulnerability.
An attacker can exploit this issue to write files in the context of the current process which leads to arbitrary code execution within the application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
NetIQ Security Manager is prone to a remote code-execution vulnerability.
An attacker can exploit this issue to write files in the context of the current process which leads to arbitrary code execution within the application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
Exploit / POC
NetIQ Security Manager 'NQMcsVarSet' ActiveX Remote Code Execution Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
NetIQ Security Manager 'NQMcsVarSet' ActiveX Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
NetIQ Security Manager 'NQMcsVarSet' ActiveX Remote Code Execution Vulnerability
References:
References:
- Novell Homepage (Novell)