CVE-2012-0241

Advantech WebAccess < 7.0 - Denial of Service via Modified Stream Identifier

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2012-0241. PoCs published by Snake.

AI-analyzed exploit summary This exploit leverages a vulnerability in the BroadWin WebAccess SCADA/HMI ActiveX component (bwocxrun.ocx) to achieve remote code execution. It creates a malicious VBScript file and uses Windows Management Instrumentation (WMI) to execute arbitrary code, specifically launching calc.exe as a proof-of-concept.

Description

Advantech/BroadWin WebAccess before 7.0 allows remote attackers to cause a denial of service (memory corruption) via a modified stream identifier to a function.

Exploits (2)

exploitdb WORKING POC
by Snake · textremotewindows
https://www.exploit-db.com/exploits/18051

This exploit leverages a vulnerability in the BroadWin WebAccess SCADA/HMI ActiveX component (bwocxrun.ocx) to achieve remote code execution. It creates a malicious VBScript file and uses Windows Management Instrumentation (WMI) to execute arbitrary code, specifically launching calc.exe as a proof-of-concept.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: BroadWin WebAccess SCADA/HMI (bwocxrun.ocx versions including v1.0.0.10 and v1.0.0.11)
No auth needed
Prerequisites: Target system with vulnerable BroadWin WebAccess ActiveX component installed · Victim must visit a malicious webpage or open a malicious HTML file
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP
doswindows
https://www.exploit-db.com/exploits/17772

The writeup details two vulnerabilities in BroadWin WebAccess Client's bwocxrun.ocx ActiveX component: a format string bug in OcxSpool and arbitrary memory corruption via WriteTextData/CloseFile. It includes technical analysis but no direct exploit code.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: BroadWin WebAccess Client bwocxrun.ocx <= 1.0.0.10
No auth needed
Prerequisites: Victim must visit a malicious webpage hosting the exploit
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/73281
Patch, US Government Resource x_refsource_misc
http://www.us-cert.gov/control_systems/pdf/ICSA-12-047-01.pdf
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/52051

Scores

EPSS 0.0496
EPSS Percentile 91.1%

Details

CWE
CWE-119
Status published
Products (2)
advantech/advantech_webaccess 5.0
advantech/advantech_webaccess < 6.0
Published Feb 21, 2012
Tracked Since Feb 18, 2026