First published: Mon Dec 05 2011(Updated: )
Stack-based buffer overflow in CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 allows remote attackers to execute arbitrary code via a crafted 0x15 (aka Remove File) operation for a file with a long name.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
InduSoft Web Studio | =6.1 | |
InduSoft Web Studio | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4052 is classified as a critical vulnerability due to its ability to allow remote code execution.
To mitigate CVE-2011-4052, update InduSoft Web Studio to version 7.1 or later, or apply the relevant patches provided by the vendor.
CVE-2011-4052 affects InduSoft Web Studio versions 6.1 and 7.0.
Organizations using vulnerable versions of InduSoft Web Studio may be at risk of exploitation by remote attackers.
CVE-2011-4052 involves a stack-based buffer overflow attack triggered by a crafted Remove File operation on a file with a long name.