Vulnerability Name:

CVE-2012-0439 (CCN-81709)

Assigned:2012-01-09
Published:2013-01-30
Updated:2013-02-25
Summary:An ActiveX control in gwcls1.dll in the client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code via (1) a pointer argument to the SetEngine method or (2) an XPItem pointer argument to an unspecified method.
CVSS v3 Severity:10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
7.7 High (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
9.3 High (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
7.7 High (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-94
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2012-0439

Source: CCN
Type: SA52031
Novell GroupWise Client Two Vulnerabilities

Source: CCN
Type: Novell Document ID: 7011688
GroupWise Client for Windows ActiveX Control Vulnerability

Source: CONFIRM
Type: Vendor Advisory
http://www.novell.com/support/kb/doc.php?id=7011688

Source: CCN
Type: BID-57658
Novell Groupwise Client CVE-2012-0439 ActiveX Control Remote Code Execution Vulnerability

Source: MISC
Type: UNKNOWN
http://www.zerodayinitiative.com/advisories/ZDI-13-008/

Source: CONFIRM
Type: UNKNOWN
https://bugzilla.novell.com/show_bug.cgi?id=712144

Source: CONFIRM
Type: UNKNOWN
https://bugzilla.novell.com/show_bug.cgi?id=743674

Source: XF
Type: UNKNOWN
groupwise-activex-code-exec(81709)

Source: CCN
Type: Packet Storm Security [02-12-2013]
Novell GroupWise Client gwcls1.dll ActiveX Remote Code Execution

Source: EXPLOIT-DB
Type: EXPLOIT
Offensive Security Exploit Database [02-12-2013]

Source: CCN
Type: ZDI-13-008
Novell GroupWise gwcls1.dll ActiveX Control Remote Code Execution Vulnerability

Vulnerable Configuration:Configuration 1:
  • cpe:/a:novell:groupwise:8.0:*:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:8.00:hp1:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:8.00:hp2:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:8.00:hp3:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:8.01:*:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:8.01:hp:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:8.02:*:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:8.02:hp1:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:8.02:hp2:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:8.02:hp3:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:8.03:*:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:8.03:hp1:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/a:novell:groupwise:2012:*:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:2012:sp1:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:novell:groupwise:8.0:*:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:8.0:hp1:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:8.0:hp2:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:8.0:sp1:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:8.01:*:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:8.02:*:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:8.02:hp3:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    novell groupwise 8.0
    novell groupwise 8.00 hp1
    novell groupwise 8.00 hp2
    novell groupwise 8.00 hp3
    novell groupwise 8.01
    novell groupwise 8.01 hp
    novell groupwise 8.02
    novell groupwise 8.02 hp1
    novell groupwise 8.02 hp2
    novell groupwise 8.02 hp3
    novell groupwise 8.03
    novell groupwise 8.03 hp1
    novell groupwise 2012
    novell groupwise 2012 sp1
    novell groupwise 8.0
    novell groupwise 8.0 hp1
    novell groupwise 8.0 hp2
    novell groupwise 8.0 sp1
    novell groupwise 8.01
    novell groupwise 8.02
    novell groupwise 8.02 hp3