PT-2018-2159 · Галактика · Галактика Erp
Published
2018-08-31
·
Updated
2018-08-31
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Галактика ERP (affected versions not specified)
Description
The issue is related to architectural weaknesses in the remote procedure call handlers of the Галактика ERP system, specifically in the atlcore .dll library. This weakness allows for the invocation of code and reading of memory content at an arbitrary address when memory addresses are transmitted between the client and server. An attacker, who has passed the authentication procedure and is acting remotely, can exploit this issue to deliver shellcode to the server's memory and transfer control to it. This is achieved by calculating a VIP language expression and writing an arbitrary set of bytes to the server's address space, revealing the address at which the write operation was performed, utilizing the
sqlAddStr API function.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Галактика Erp