CVE-2014-0773

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/04/2014
Last modified:
14/04/2014

Description

The CreateProcess method in the BWOCXRUN.BwocxrunCtrl.1 ActiveX control in bwocxrun.ocx in Advantech WebAccess before 7.2 allows remote attackers to execute (1) setup.exe, (2) bwvbprt.exe, and (3) bwvbprtl.exe programs from arbitrary pathnames via a crafted argument, as demonstrated by a UNC share pathname.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:advantech:advantech_webaccess:*:*:*:*:*:*:*:* 7.1 (including)
cpe:2.3:a:advantech:advantech_webaccess:5.0:*:*:*:*:*:*:*
cpe:2.3:a:advantech:advantech_webaccess:6.0:*:*:*:*:*:*:*
cpe:2.3:a:advantech:advantech_webaccess:7.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools