CVE-2014-0773

The CreateProcess method in the BWOCXRUN.BwocxrunCtrl.1 ActiveX control in bwocxrun.ocx in Advantech WebAccess before 7.2 allows remote attackers to execute (1) setup.exe, (2) bwvbprt.exe, and (3) bwvbprtl.exe programs from arbitrary pathnames via a crafted argument, as demonstrated by a UNC share pathname.
References
Link Resource
http://ics-cert.us-cert.gov/advisories/ICSA-14-079-03 US Government Resource
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:advantech:advantech_webaccess:*:*:*:*:*:*:*:*
cpe:2.3:a:advantech:advantech_webaccess:5.0:*:*:*:*:*:*:*
cpe:2.3:a:advantech:advantech_webaccess:6.0:*:*:*:*:*:*:*
cpe:2.3:a:advantech:advantech_webaccess:7.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2014-04-12 04:37

Updated : 2023-12-10 11:31


NVD link : CVE-2014-0773

Mitre link : CVE-2014-0773

CVE.ORG link : CVE-2014-0773


JSON object : View

Products Affected

advantech

  • advantech_webaccess