| Vulnerability Name: | CVE-2011-2657 (CCN-70755) | ||||||||
| Assigned: | 2011-10-18 | ||||||||
| Published: | 2011-10-18 | ||||||||
| Updated: | 2012-07-27 | ||||||||
| Summary: | Directory traversal vulnerability in the LaunchProcess function in the LaunchHelp.HelpLauncher.1 ActiveX control in LaunchHelp.dll in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.2, 10.3, and 11 SP1 allows remote attackers to execute arbitrary commands via a pathname in the first argument. | ||||||||
| CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
| CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.6 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:F/RL:OF/RC:C)
7.7 High (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-22 | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: MITRE Type: CNA CVE-2011-2657 Source: CCN Type: Packetstorm Security Website AdminStudio LaunchHelp.dll ActiveX Arbitrary Code Execution Source: CCN Type: SA46466 Novell ZENworks Configuration Management AdminStudio ActiveX Controls Vulnerabilities Source: EXPLOIT-DB Type: Exploit 19718 Source: CONFIRM Type: Patch, Vendor Advisory http://www.novell.com/support/kb/doc.php?id=7009570 Source: CCN Type: Novell Document ID: 7009570 Security Vulnerabilities with ZENworks Admin Studio version Source: CCN Type: OSVDB ID: 76700 Novell ZENworks Software Packaging ActiveX (LaunchHelp.dll) LaunchProcess Function Remote Code Execution Source: CCN Type: BID-50274 Novell ZENworks Configuration Management AdminStudio Remote Code Execution Vulnerabilities Source: MISC Type: UNKNOWN http://www.zerodayinitiative.com/advisories/ZDI-11-318/ Source: XF Type: UNKNOWN zenworks-launchhelpdall-code-exec(70755) Source: EXPLOIT-DB Type: EXPLOIT EDB-ID: 19718 Source: CCN Type: ZDI-11-318 Novell Zenworks Software Packaging LaunchHelp.dll ActiveX Control LaunchProcess Remote Code Execution Vulnerability | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||