vendor:
InTouch Machine Edition
by:
Luis Martinez
7.8
CVSS
HIGH
Local Buffer Overflow (SEH Unicode)
119
CWE
Product Name: InTouch Machine Edition
Affected Version From: 8.1 SP1
Affected Version To: 8.1 SP1
Patch Exists: YES
Related CWE: N/A
CPE: a:wonderware:intouch_machine_edition:8.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Pro x64 en
2018
InTouch Machine Edition 8.1 SP1 – ‘Nombre del Tag’ Buffer Overflow (SEH)
A local buffer overflow vulnerability exists in InTouch Machine Edition 8.1 SP1 due to improper bounds checking of user-supplied input. An attacker can exploit this vulnerability by running a specially crafted python code and copying the content to clipboard, then pasting it on 'Nombre del Tag' field. This can result in arbitrary code execution.
Mitigation:
Upgrade to the latest version of InTouch Machine Edition 8.1 SP1.