RULE(RULE ID:310005)

Rule General Information
Release Date: 2016-01-11
Rule Name: WEB-ACTIVEX ICONICS Webhmi Activex Control Stack Buffer Overflow Vulnerability (CVE-2011-2089)
Severity:
CVE ID:
Rule Protection Details
Description: Stack-based buffer overflow in the SetActiveXGUID method in the VersionInfo ActiveX control in GenVersion.dll 8.0.138.0 in the WebHMI subsystem in ICONICS BizViz 9.x before 9.22 and GENESIS32 9.x before 9.22 allows remote attackers to execute arbitrary code via a long string in the argument.
Impact: A buffer overflow vulnerability can be triggered by an attacker in the context of the vulnerable product. Further attacks includes arbitrary code execution and denial of service.
Affected OS: Windows
Reference: ExploitDB:17240
ExploitDB:17269
SecurityFocusBID:47704
Solutions
Upgrade to version 9.1 to solve the problem.