PT-2011-2416 · Sielco Sistemi · Winlog Pro

Luigi Auriemma

·

Published

2011-01-20

·

Updated

2017-08-17

·

CVE-2011-0517

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Sielco Sistemi Winlog Pro versions 2.07.00 and earlier
Description The issue is related to a stack-based buffer overflow that can be triggered when the "Run TCP/IP server" is enabled. This allows remote attackers to cause a denial of service (crash) and potentially execute arbitrary code by sending a crafted 0x02 opcode to TCP port 46823.
Recommendations For versions 2.07.00 and earlier, disable the "Run TCP/IP server" feature to prevent exploitation until a patch is available. As a temporary workaround, consider restricting access to TCP port 46823 to minimize the risk of remote attacks.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-0517

Affected Products

Winlog Pro