PT-2011-2279 · Indusoft+1 · Indusoft Web Studio+2

Published

2011-05-04

·

Updated

2013-05-21

·

CVE-2011-0340

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions InduSoft Web Studio versions prior to 7.0+SP1 InduSoft Thin Client version 7.0 Advantech Studio version 6.1 SP6 61.6.01.05
Description The issue allows remote attackers to execute arbitrary code via a long value in certain properties or method arguments, including InternationalOrder, InternationalSeparator, or LogFileName property values, or a long bstrFileName argument to the OpenScreen method.
Recommendations For InduSoft Web Studio versions prior to 7.0+SP1, update to version 7.0+SP1 or later. For InduSoft Thin Client version 7.0, consider disabling the OpenScreen method or restricting access to the ISSymbol ActiveX control until a patch is available. For Advantech Studio version 6.1 SP6 61.6.01.05, restrict the use of long values in the InternationalOrder, InternationalSeparator, or LogFileName properties to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-0340
ZDI-12-155
ZDI-12-168

Affected Products

Advantech Studio
Indusoft Thin Client
Indusoft Web Studio