CVE-2011-2089: Buffer Overflow
Stack-based buffer overflow in the SetActiveXGUID method in the VersionInfo ActiveX control in GenVersion.dll 8.0.138.0 in the WebHMI subsystem in ICONICS BizViz 9.x before 9.22 and GENESIS32 9.x before 9.22 allows remote attackers to execute arbitrary code via a long string in the argument. NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2089?
CVE-2011-2089 has a high severity due to the potential for remote code execution.
How do I fix CVE-2011-2089?
To fix CVE-2011-2089, update your ICONICS BizViz or GENESIS32 software to version 9.22 or later.
Who is affected by CVE-2011-2089?
CVE-2011-2089 affects users of ICONICS BizViz versions 9.0, 9.01, 9.1, 9.2, 9.13, 9.20, 9.21 and GENESIS32 versions 9.0, 9.01, 9.1, 9.2, 9.13, 9.20, 9.21.
What type of vulnerability is CVE-2011-2089?
CVE-2011-2089 is a stack-based buffer overflow vulnerability.
Can CVE-2011-2089 be exploited remotely?
Yes, CVE-2011-2089 can be exploited remotely by sending a specially crafted long string to the vulnerable ActiveX control.