CVE-2011-2089

ICONICS BizViz <9.22, GENESIS32 <9.22 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2011-2089. PoCs published by Metasploit, sgb & bls, including Metasploit module exploits/windows/scada/iconics_webhmi_setactivexguid.

AI-analyzed exploit summary This Metasploit module exploits a buffer overflow in ICONICS WebHMI's ActiveX control via the 'SetActiveXGUID' parameter, leading to arbitrary code execution. It uses ROP techniques for IE 8 on Windows XP SP3 and heap spraying for other targets.

Description

Stack-based buffer overflow in the SetActiveXGUID method in the VersionInfo ActiveX control in GenVersion.dll 8.0.138.0 in the WebHMI subsystem in ICONICS BizViz 9.x before 9.22 and GENESIS32 9.x before 9.22 allows remote attackers to execute arbitrary code via a long string in the argument. NOTE: some of these details are obtained from third party information.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/17269

This Metasploit module exploits a buffer overflow in ICONICS WebHMI's ActiveX control via the 'SetActiveXGUID' parameter, leading to arbitrary code execution. It uses ROP techniques for IE 8 on Windows XP SP3 and heap spraying for other targets.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: ICONICS WebHMI (GenVersion.dll ActiveX control)
No auth needed
Prerequisites: Target must visit a malicious webpage · ActiveX control must be installed and enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by sgb & bls · htmlremotewindows
https://www.exploit-db.com/exploits/17240

This is a working proof-of-concept exploit for CVE-2011-2089, targeting a stack overflow vulnerability in the ICONICS WebHMI ActiveX control (GenVersion.dll). The exploit uses a ROP chain to achieve arbitrary code execution via a crafted JavaScript payload.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: ICONICS Genesis32 WebHMI ActiveX control (GenVersion.dll) with ClassID {CEFF5F48-BD2E-4D10-BAE5-AF729975E223}
No auth needed
Prerequisites: Victim must have the vulnerable ActiveX control installed · Victim must visit a malicious webpage hosting the exploit
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC GOOD
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/scada/iconics_webhmi_setactivexguid.rb

This Metasploit module exploits a buffer overflow in ICONICS WebHMI's ActiveX control via the 'SetActiveXGUID' parameter, leading to arbitrary code execution. It uses ROP techniques for specific targets and heap spraying for others.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: ICONICS WebHMI (GenVersion.dll)
No auth needed
Prerequisites: Victim must visit a malicious webpage · ActiveX control must be enabled in the browser
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/72135
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/44417
US Government Resource x_refsource_misc
http://www.us-cert.gov/control_systems/pdf/ICSA-11-131-01.pdf
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/1174
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/47704
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/17240
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/17269
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/67267

Scores

EPSS 0.3846
EPSS Percentile 98.4%

Details

CWE
CWE-119
Status published
Products (14)
iconics/bizviz 9.0
iconics/bizviz 9.01
iconics/bizviz 9.1
iconics/bizviz 9.2
iconics/bizviz 9.13
iconics/bizviz 9.20
iconics/bizviz 9.21
iconics/genesis32 9.0
iconics/genesis32 9.1
iconics/genesis32 9.01
... and 4 more
Published May 13, 2011
Tracked Since Feb 18, 2026