First published: Fri Nov 14 2014(Updated: )
Rockwell Automation Connected Components Workbench (CCW) before 7.00.00 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an invalid property value to an ActiveX control that was built with an outdated compiler.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Rockwell Automation Connected Components Workbench | <=6.01.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-5424 is classified as a high-severity vulnerability due to its potential for remote denial of service and arbitrary code execution.
To mitigate CVE-2014-5424, upgrade Connected Components Workbench to version 7.00.00 or later.
CVE-2014-5424 affects all versions of Rockwell Automation Connected Components Workbench prior to 7.00.00.
CVE-2014-5424 is a vulnerability that allows for denial of service and potential arbitrary code execution due to improper handling of ActiveX control properties.
Yes, CVE-2014-5424 can be exploited remotely by attackers to crash the application or execute arbitrary code.