vendor:
WinRDS
by:
Praveen Darshanam
9.8
CVSS
CRITICAL
Stack Buffer Overflow
121
CWE
Product Name: WinRDS
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2015-2094
CPE: a:webgate:winrds
Platforms Tested: Windows XP SP3 using IE6/7/8
2015
WebGate WinRDS PlaySiteAllChannel Stack Buffer Overflow
The WebGate WinRDS PlaySiteAllChannel function in WESPPlayback.dll is vulnerable to a stack buffer overflow. By sending a specially crafted argument to the function, an attacker can overwrite the stack and execute arbitrary code.
Mitigation:
Update to a patched version of the software. Avoid passing untrusted input to the vulnerable function.