PT-2015-7669 · Schneider Electric · Proclima

Ariele Caltabiano

·

Published

2015-12-08

·

Updated

2015-12-16

·

CVE-2015-7918

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Schneider Electric ProClima versions prior to 6.2
Description The issue is related to multiple buffer overflows in the F1BookView ActiveX control, allowing remote attackers to execute arbitrary code via various methods, including Attach, DefinedName, DefinedNameLocal, ODBCPrepareEx, ObjCreatePolygon, SetTabbedTextEx, and SetValidationRule.
Recommendations For versions prior to 6.2, update to version 6.2 or later to resolve the issue. As a temporary workaround, consider disabling the Attach, DefinedName, DefinedNameLocal, ODBCPrepareEx, ObjCreatePolygon, SetTabbedTextEx, and SetValidationRule methods until a patch is available. Restrict access to the F1BookView ActiveX control to minimize the risk of exploitation.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-7918
ZDI-15-625
ZDI-15-630
ZDI-15-631
ZDI-15-632
ZDI-15-633
ZDI-15-634
ZDI-15-635

Affected Products

Proclima