PT-2018-2159 · Галактика · Галактика Erp

Published

2018-08-31

·

Updated

2018-08-31

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Галактика ERP (affected versions not specified)
Description The issue is related to architectural weaknesses in the remote procedure call handlers of the Галактика ERP system, specifically in the atlcore .dll library. This weakness allows for the invocation of code and reading of memory content at an arbitrary address when memory addresses are transmitted between the client and server. An attacker, who has passed the authentication procedure and is acting remotely, can exploit this issue to deliver shellcode to the server's memory and transfer control to it. This is achieved by calculating a VIP language expression and writing an arbitrary set of bytes to the server's address space, revealing the address at which the write operation was performed, utilizing the sqlAddStr API function.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-00112

Affected Products

Галактика Erp