E13-3vh01
CVSS:
6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P)
False Positive:
t
Variants:
1
Year:
2013
Description
This strike identifies a vulnerability in an Indusoft ThinClient ActiveX control. The Initialize2 method does not properly validate its arguments. If a malicious or overly large string size is used and exceeds the limit of the buffer, an overflow will occur allowing for remote code to be executed.
CVE
References
MSB
BID
ExploitDB
Secunia
Security Tracker
Metasploit
ZDI
OSVDB
{98333}