// For flags

CVE-2013-1079

Novell ZENWorks AdminStudio ISProxy ActiveX Remote Code Execution Vulnerability

Severity Score

6.8
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Directory traversal vulnerability in the ISCreateObject method in an ActiveX control in InstallShield\ISProxy.dll in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.3 through 11.2 allows remote attackers to execute arbitrary local DLL files via a crafted web page that also calls the Initialize method.

Vulnerabilidad de salto de directorio en el método ISCreateObject en un control ActiveX en InstallShield\ISProxy.dll en AdminStudio in Novell ZENworks Configuration Management (ZCM) v10.3 hasta v11.2 permite a atacantes remotos ejecutar archivos DLL locales a través de una página web manipulada para que también llame al método Initialize.

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Novell ZENworks Admin Studio. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the ISProxy.dll ActiveX object. The ISCreateObject() method suffers from a directory vulnerability and it is also possible to break the search path through a null char. By combining the Initialize() and ISCreateObject() methods, an attacker can force the underlying operating system to load arbitrary dlls bypassing normal security restriction. This vulnerability allows an attacker to execute code under the context of the process.

*Credits: Andrea Micalizzi aka rgod
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2013-01-11 CVE Reserved
  • 2013-03-22 CVE Published
  • 2024-09-16 CVE Updated
  • 2024-10-27 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Novell
Search vendor "Novell"
Zenworks Configuration Management
Search vendor "Novell" for product "Zenworks Configuration Management"
10.3
Search vendor "Novell" for product "Zenworks Configuration Management" and version "10.3"
-
Affected
Novell
Search vendor "Novell"
Zenworks Configuration Management
Search vendor "Novell" for product "Zenworks Configuration Management"
10.3.1
Search vendor "Novell" for product "Zenworks Configuration Management" and version "10.3.1"
-
Affected
Novell
Search vendor "Novell"
Zenworks Configuration Management
Search vendor "Novell" for product "Zenworks Configuration Management"
10.3.2
Search vendor "Novell" for product "Zenworks Configuration Management" and version "10.3.2"
-
Affected
Novell
Search vendor "Novell"
Zenworks Configuration Management
Search vendor "Novell" for product "Zenworks Configuration Management"
10.3.3
Search vendor "Novell" for product "Zenworks Configuration Management" and version "10.3.3"
-
Affected
Novell
Search vendor "Novell"
Zenworks Configuration Management
Search vendor "Novell" for product "Zenworks Configuration Management"
11
Search vendor "Novell" for product "Zenworks Configuration Management" and version "11"
-
Affected
Novell
Search vendor "Novell"
Zenworks Configuration Management
Search vendor "Novell" for product "Zenworks Configuration Management"
11.1
Search vendor "Novell" for product "Zenworks Configuration Management" and version "11.1"
-
Affected
Novell
Search vendor "Novell"
Zenworks Configuration Management
Search vendor "Novell" for product "Zenworks Configuration Management"
11.1a
Search vendor "Novell" for product "Zenworks Configuration Management" and version "11.1a"
-
Affected
Novell
Search vendor "Novell"
Zenworks Configuration Management
Search vendor "Novell" for product "Zenworks Configuration Management"
11.2
Search vendor "Novell" for product "Zenworks Configuration Management" and version "11.2"
-
Affected