ID

VAR-190001-0555


TITLE

Movicon 'dwmapi.dll' DLL Load arbitrary code execution vulnerability

Trust: 1.0

sources: IVD: 7d7f4ecf-463f-11e9-b367-000c29342cb1 // IVD: 6fa228cc-1f88-11e6-abef-000c29c66e3d // CNNVD: CNNVD-201109-189

DESCRIPTION

Movicon is the first fully XML-based Scada/HMI software developed by the famous Italian automation software provider PROGEA. There is an arbitrary code execution vulnerability in Movicon 11.2 Build 1085 and other versions of dwmapi.dll. A remote attacker can open a file on a network share containing a specially crafted dynamic link library (DLL) file by tricking legitimate users into using the affected application

Trust: 1.17

sources: CNVD: CNVD-2011-6048 // BID: 49604 // IVD: 7d7f4ecf-463f-11e9-b367-000c29342cb1 // IVD: 6fa228cc-1f88-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 1.0

sources: IVD: 7d7f4ecf-463f-11e9-b367-000c29342cb1 // IVD: 6fa228cc-1f88-11e6-abef-000c29c66e3d // CNVD: CNVD-2011-6048

AFFECTED PRODUCTS

vendor:nomodel: - scope: - version: -

Trust: 0.6

vendor:progeamodel:movicon buildscope:eqversion:11.21085

Trust: 0.3

sources: CNVD: CNVD-2011-6048 // BID: 49604

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2011-6048
value: HIGH

Trust: 0.6

IVD: 7d7f4ecf-463f-11e9-b367-000c29342cb1
value: HIGH

Trust: 0.2

IVD: 6fa228cc-1f88-11e6-abef-000c29c66e3d
value: HIGH

Trust: 0.2

CNVD: CNVD-2011-6048
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: 7d7f4ecf-463f-11e9-b367-000c29342cb1
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

IVD: 6fa228cc-1f88-11e6-abef-000c29c66e3d
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: 7d7f4ecf-463f-11e9-b367-000c29342cb1 // IVD: 6fa228cc-1f88-11e6-abef-000c29c66e3d // CNVD: CNVD-2011-6048

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201109-189

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-201109-189

EXTERNAL IDS

db:BIDid:49604

Trust: 1.5

db:CNVDid:CNVD-2011-6048

Trust: 1.0

db:CNNVDid:CNNVD-201109-189

Trust: 0.6

db:IVDid:7D7F4ECF-463F-11E9-B367-000C29342CB1

Trust: 0.2

db:IVDid:6FA228CC-1F88-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: 7d7f4ecf-463f-11e9-b367-000c29342cb1 // IVD: 6fa228cc-1f88-11e6-abef-000c29c66e3d // CNVD: CNVD-2011-6048 // BID: 49604 // CNNVD: CNNVD-201109-189

REFERENCES

url:http://www.securityfocus.com/bid/49604/

Trust: 0.6

url:http://www.securityfocus.com/bid/49604

Trust: 0.6

url:http://blog.rapid7.com/?p=5325

Trust: 0.3

url:http://blog.metasploit.com/2010/08/exploiting-dll-hijacking-flaws.html

Trust: 0.3

url:http://blogs.technet.com/b/msrc/archive/2010/08/21/microsoft-security-advisory-2269637-released.aspx

Trust: 0.3

url:http://blogs.technet.com/b/srd/archive/2010/08/23/more-information-about-dll-preloading-remote-attack-vector.aspx

Trust: 0.3

url:http://www.progea.com/

Trust: 0.3

url:http://www.microsoft.com/technet/security/advisory/2269637.mspx

Trust: 0.3

sources: CNVD: CNVD-2011-6048 // BID: 49604 // CNNVD: CNNVD-201109-189

CREDITS

Mister Teatime

Trust: 0.9

sources: BID: 49604 // CNNVD: CNNVD-201109-189

SOURCES

db:IVDid:7d7f4ecf-463f-11e9-b367-000c29342cb1
db:IVDid:6fa228cc-1f88-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2011-6048
db:BIDid:49604
db:CNNVDid:CNNVD-201109-189

LAST UPDATE DATE

2022-05-17T02:02:15.629000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2011-6048date:2011-09-15T00:00:00
db:BIDid:49604date:2011-09-13T00:00:00
db:CNNVDid:CNNVD-201109-189date:2011-09-15T00:00:00

SOURCES RELEASE DATE

db:IVDid:7d7f4ecf-463f-11e9-b367-000c29342cb1date:2011-09-15T00:00:00
db:IVDid:6fa228cc-1f88-11e6-abef-000c29c66e3ddate:2011-09-15T00:00:00
db:CNVDid:CNVD-2011-6048date:2011-09-15T00:00:00
db:BIDid:49604date:2011-09-13T00:00:00
db:CNNVDid:CNNVD-201109-189date:1900-01-01T00:00:00