vendor:
Quality Center
by:
Titon and Ri0t of Bastardlabs
9
CVSS
CRITICAL
Buffer Overflow
CWE
Product Name: Quality Center
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
POC exploit for Mercury Quality Center Spider90.ocx ProgColor Overflow
This is a proof of concept (POC) exploit for the Mercury Quality Center Spider90.ocx ProgColor Overflow vulnerability. The exploit takes advantage of a buffer overflow vulnerability in the Spider90.ocx ActiveX control to execute arbitrary code.
Mitigation:
Apply the latest patches and updates from the vendor. Consider disabling or removing the vulnerable ActiveX control if it is not needed.