Advantech AdamView CVE-2014-8386 Multiple Stack Based Buffer Overflow Vulnerabilities
BID:71191
Info
Advantech AdamView CVE-2014-8386 Multiple Stack Based Buffer Overflow Vulnerabilities
| Bugtraq ID: | 71191 |
| Class: | Design Error |
| CVE: |
CVE-2014-8386 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 19 2014 12:00AM |
| Updated: | Jul 15 2015 12:14AM |
| Credit: | CORE Advisories Team |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Advantech AdamView CVE-2014-8386 Multiple Stack Based Buffer Overflow Vulnerabilities
Advantech AdamView is prone to multiple stack-based buffer overflow vulnerabilities with in the ActiveX control because the application fails to properly bounds-check user-supplied data before copying them into an insufficiently sized buffer.
Attackers can exploit these issues to execute arbitrary code in the context of the affected application (typically Internet Explorer) using the ActiveX control. Failed exploit attempts likely result in denial-of-service conditions.
Advantech AdamView 4.3 is vulnerable; other versions may also be affected.
Advantech AdamView is prone to multiple stack-based buffer overflow vulnerabilities with in the ActiveX control because the application fails to properly bounds-check user-supplied data before copying them into an insufficiently sized buffer.
Attackers can exploit these issues to execute arbitrary code in the context of the affected application (typically Internet Explorer) using the ActiveX control. Failed exploit attempts likely result in denial-of-service conditions.
Advantech AdamView 4.3 is vulnerable; other versions may also be affected.
Exploit / POC
Advantech AdamView CVE-2014-8386 Multiple Stack Based Buffer Overflow Vulnerabilities
An attacker can exploit these issues by enticing an unsuspecting user to view a malicious webpage.
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
An attacker can exploit these issues by enticing an unsuspecting user to view a malicious webpage.
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Advantech AdamView CVE-2014-8386 Multiple Stack Based Buffer Overflow Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Advantech AdamView CVE-2014-8386 Multiple Stack Based Buffer Overflow Vulnerabilities
References:
References:
- Microsoft Support Document 240797 (Microsoft)