vendor:
Rumba
by:
Umit Aksu
9,8
CVSS
CRITICAL
Stack-based buffer overflow
119
CWE
Product Name: Rumba
Affected Version From: 9.3
Affected Version To: 9.4.x
Patch Exists: YES
Related CWE: CVE-2016-5228
CPE: a:micro_focus:rumba
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Internet Explorer 11 on Windows 7
2016
Micro Focus Rumba <= 9.3 ActiveX Stack-based buffer overflow
Stack-based buffer overflow in the PlayMacro function in ObjectXMacro.ObjectXMacro in WdMacCtl.ocx in Micro Focus Rumba 9.x before 9.3 HF 11997 and 9.4.x before 9.4 HF 12815 allows remote attackers to execute arbitrary code via a long MacroName argument.
Mitigation:
Update to the latest version of Micro Focus Rumba