First published: Thu Jul 26 2012(Updated: )
The ISList.ISAvi ActiveX control in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.2, 10.3, and 11 SP1 provides access to the mscomct2.ocx file, which allows remote attackers to execute arbitrary code by leveraging unspecified mscomct2 flaws.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Micro Focus ZENworks Configuration Management | =11-sp1 | |
Micro Focus ZENworks Configuration Management | =10.2 | |
Micro Focus ZENworks Configuration Management | =10.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-2658 has a critical severity rating due to the potential for remote code execution.
The recommended fix for CVE-2011-2658 is to upgrade to a patched version of Novell ZENworks Configuration Management.
CVE-2011-2658 affects Novell ZENworks Configuration Management versions 10.2, 10.3, and 11 SP1.
The main risk associated with CVE-2011-2658 is that attackers can execute arbitrary code remotely on vulnerable systems.
There are no known effective workarounds for CVE-2011-2658, so upgrading is the best course of action.