CVE-2007-6033: Critical severity Wonderware InTouch vulnerability
Invensys Wonderware InTouch 8.0 creates a NetDDE share with insecure permissions (Everyone/Full Control), which allows remote authenticated attackers, and possibly anonymous users, to execute arbitrary programs.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-6033?
CVE-2007-6033 is considered a critical vulnerability due to its potential to allow remote authenticated attackers to execute arbitrary programs.
How do I fix CVE-2007-6033?
To resolve CVE-2007-6033, it's important to modify the NetDDE share permissions to restrict access from Everyone and limit it to only necessary users.
What versions are affected by CVE-2007-6033?
CVE-2007-6033 specifically affects Invensys Wonderware InTouch version 8.0.
Can anonymous users exploit CVE-2007-6033?
Yes, CVE-2007-6033 may allow anonymous users to exploit the vulnerability if the NetDDE share permissions are not properly configured.
What type of access does CVE-2007-6033 provide to attackers?
CVE-2007-6033 provides attackers with full control access, enabling them to execute arbitrary programs on the affected system.