vendor:
AdminStudio
by:
rgod, juan
7,6
CVSS
HIGH
Arbitrary Code Execution
94
CWE
Product Name: AdminStudio
Affected Version From: 9.5.0.0
Affected Version To: 9.5.0.0
Patch Exists: YES
Related CWE: CVE-2011-2657
CPE: a:flexerasoftware:adminstudio
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP 3
2011
AdminStudio LaunchHelp.dll ActiveX Arbitrary Code Execution
This module exploits a vulnerability in AdminStudio LaunchHelp.dll ActiveX control. The LaunchProcess function found in LaunchHelp.HelpLauncher.1 allows remote attackers to run arbitrary commands on the victim machine. This module has been successfully tested with the ActiveX installed with AdminStudio 9.5, which also comes with Novell ZENworks Configuration Management 10 SP2, on IE 6 and IE 8 over Windows XP SP 3.
Mitigation:
Update to the latest version of AdminStudio LaunchHelp.dll ActiveX control.