HTTP: Advantech Studio ISSymbol Unsafe ActiveX Control Multiple Buffer Overflow

This signature detects attempts to exploit a known vulnerability in Advantech Studio. An attacker can create a Web site containing Web pages with dangerous ActiveX calls, which if accessed by a victim, allows the attacker to gain control of the victim's client browser.

Extended Description

The Advantech Studio ISSymbol ActiveX control is prone to multiple buffer-overflow vulnerabilities because the application fails to perform adequate boundary checks on user-supplied input. Attackers may exploit these issues to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts will likely result in denial-of-service conditions. Advantech Studio 6.1 SP6 Build 61.6.01.05 is vulnerable; other versions may also be affected.

Affected Products

Indusoft web_studio

Short Name
HTTP:STC:ACTIVEX:ISSYMBOL
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
ActiveX Advantech Buffer CVE-2011-0340 CVE-2011-0342 Control ISSymbol Multiple Overflow Studio Unsafe bid:47596 bid:49403
Release Date
05/16/2011
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Advantech

Indusoft

CVSS Score

9.3

10.0

Found a potential security threat?