First published: Thu Mar 20 2014(Updated: )
Stack-based buffer overflow in the "Add from text file" feature in the DameWare Exporter tool (DWExporter.exe) in DameWare Remote Support 10.0.0.372, 9.0.1.247, and earlier allows user-assisted attackers to execute arbitrary code via unspecified vectors.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds Dameware Remote Support | <=9.0.1.247 | |
SolarWinds Dameware Remote Support | >=10.0<=10.0.0.372 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3249 has a high severity rating due to its potential to allow arbitrary code execution.
To fix CVE-2013-3249, users should upgrade to the latest version of DameWare Remote Support that addresses this vulnerability.
DameWare Remote Support versions 9.0.1.247 and earlier, as well as versions up to 10.0.0.372, are affected by CVE-2013-3249.
No, CVE-2013-3249 requires user assistance for exploitation, typically through opening a manipulated text file.
CVE-2013-3249 is classified as a stack-based buffer overflow vulnerability.