vendor:
Solid Edge ST4/ST5
by:
N/A
CVSS
HIGH
Arbitrary Memory Rewrite Remote Code Execution
CWE
Product Name: Solid Edge ST4/ST5
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows Server 2003 r2 sp2, Windows XP sp3, Windows 7, Internet Explorer 7/8
SIEMENS Solid Edge ST4/ST5 SEListCtrlX ActiveX Control SetItemReadOnly Arbitrary Memory Rewrite Remote Code Execution Vulnerability
By setting to a memory address the first argument and the second one to 'false' you can write a NULL byte inside an arbitrary memory region. By setting to a memory address the first argument and the second one to 'true' you can write a x08 byte inside an arbitrary memory region.