vendor:
KingScada
by:
Andrea Micalizzi, Juan Vazquez
7.5
CVSS
HIGH
Remote Code Execution
89
CWE
Product Name: KingScada
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2013-2827
CPE: a:wellingtech:kingscada
Platforms Tested: Windows
2014
KingScada kxClientDownload.ocx ActiveX Remote Code Execution
This module abuses the kxClientDownload.ocx ActiveX control distributed with WellingTech KingScada. The ProjectURL property can be abused to download and load arbitrary DLLs from arbitrary locations, leading to arbitrary code execution, because of a dangerous usage of LoadLibrary. Due to the nature of the vulnerability, this module will work only when Protected Mode is not present or not enabled.
Mitigation:
Apply the vendor patch.