Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2011-3142

Overview

Vulnerability Score 10.0 10.0
CVE Id CVE-2011-3142
Last Modified 16 Mar 2012 12:00:00
Published 16 Aug 2011 05:55:01
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2011-3142

Summary

Stack-based buffer overflow in an ActiveX control in KVWebSvr.dll in WellinTech KingView 6.52 and 6.53 allows remote attackers to execute arbitrary code via a long second argument to the ValidateUser method.

Vulnerable Systems

Application

  • Wellintech Kingview 6.52

  • Wellintech Kingview 6.53


References

MISC - http://www.us-cert.gov/control_systems/pdf/ICSA-11-074-01.pdf

MISC - http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-11-066-01.pdf

BID - 46757

MISC - http://www.scadahacker.com/exploits-wellintech-kvwebsvr.html

OSVDB - 72889

CONFIRM - http://www.kingview.com/news/detail.aspx?contentid=537

EXPLOIT-DB - 16936

MISC - http://www.cnvd.org.cn/vulnerability/CNVD-2011-04541


Last Updated: 27 May 2016 10:57:14