vendor:
ZENworks Configuration Management
by:
Luigi Auriemma, juan
7,5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: ZENworks Configuration Management
Affected Version From: Novell ZENworks Configuration Management 10 SP3
Affected Version To: Windows 2003 SP2
Patch Exists: YES
Related CWE: CVE-2011-3176
CPE: Novell ZENworks Configuration Management 10 SP3, Windows 2003 SP2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2011
Novell ZENworks Configuration Management Preboot Service 0x4c Buffer Overflow
This module exploits a remote buffer overflow in the ZENworks Configuration Management. The vulnerability exists in the Preboot service and can be triggered by sending a specially crafted packet with the opcode 0x4c (PROXY_CMD_PREBOOT_TASK_INFO2) to port 998/TCP. The module has been successfully tested on Novell ZENworks Configuration Management 10 SP2 / SP3 and Windows Server 2003 SP2 (DEP bypass).
Mitigation:
Novell has released a patch for this vulnerability.