Lucene search

K
kasperskyKaspersky LabKLA10358
HistoryJan 08, 2009 - 12:00 a.m.

KLA10358 ACE vulnerability in multiple products

2009-01-0800:00:00
Kaspersky Lab
threats.kaspersky.com
20

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.7 High

AI Score

Confidence

Low

0.816 High

EPSS

Percentile

98.4%

Buffer overflows were found in multiple products. By exploiting these vulnerabilities malicious users can execute arbitrary code. This vulnerability can be exploited remotely via specially designed tabs.

Original advisories

Related products

TSC2-Help-Desk

ComponentOne-Studio-Enterprise-2005

SAP-GUI

CVE list

CVE-2008-4827 critical

Solution

Update to latest version

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

Affected Products

  • ComponentOne Studio version for ActiveX 2008TSC2 Help Desk version 4.1.8SAP GUI versions 6.40 Patch 29 and 7.10

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.7 High

AI Score

Confidence

Low

0.816 High

EPSS

Percentile

98.4%