HTTP: Schneider Electric ProClima Unsafe ActiveX Control
This signature detects attempts to use unsafe ActiveX controls in Schneider Electric ProClima. The vulnerability is due to a flaw in several methods of the F1BookView ActiveX control, in which a user-supplied integer is interpreted as a memory address. An attacker can create a malicious Web site containing Web pages with dangerous ActiveX controls, which if accessed by a victim, allows the attacker to gain control of the victim's client browser.
Extended Description
The F1BookView ActiveX control in F1 Bookview in Schneider Electric ProClima before 6.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted integer value to the (1) AttachToSS, (2) CopyAll, (3) CopyRange, (4) CopyRangeEx, or (5) SwapTable method, a different vulnerability than CVE-2015-7918.
Affected Products
Schneider-electric proclima
References
CVE: CVE-2015-8561
URL: http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2015-329-01 https://ics-cert.us-cert.gov/advisories/ICSA-15-335-02 http://www.zerodayinitiative.com/advisories/zdi-15-627/ http://download.schneider-electric.com/library/downloads/ww/en/document/sevd-2015-329-01 http://www.zerodayinitiative.com/advisories/zdi-15-626/ http://www.zerodayinitiative.com/advisories/zdi-15-629/
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Schneider-electric
6.8