PT-2021-19673 · Emtec · Emtec Zoc

Published

2021-06-06

·

Updated

2021-09-21

·

CVE-2021-32198

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: EmTec ZOC versions prior to 8.02.5
Description: The issue allows remote servers to cause a denial of service, resulting in a Windows GUI hang. This occurs when the ZOC window is told to change its title repeatedly at high speed, leading to many SetWindowTextA or SetWindowTextW calls. The problem arises from the lack of a delay, such as usleep, upon processing a title change.
Recommendations: For EmTec ZOC versions prior to 8.02.5, update to version 8.02.5 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-32198

Affected Products

Emtec Zoc