CVE-2017-12969
HIGHAvaya IP Office Contact Center < 10.1.1 - Remote Code Execution via ViewerCtrl ActiveX Buffer Overflow
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-12969. PoCs published by hyp3rlinx.
AI-analyzed exploit summary This exploit demonstrates a buffer overflow vulnerability in the ViewerCtrl.ocx ActiveX component used by Avaya IP Office (IPO) versions 9.1.0 to 10.1. The PoC triggers an access violation by passing a long string of 'A' characters to the 'open' method, potentially leading to arbitrary code execution.
Description
Buffer overflow in the ViewerCtrlLib.ViewerCtrl ActiveX control in Avaya IP Office Contact Center before 10.1.1 allows remote attackers to cause a denial of service (heap corruption and crash) or execute arbitrary code via a long string to the open method.
Exploits (1)
This exploit demonstrates a buffer overflow vulnerability in the ViewerCtrl.ocx ActiveX component used by Avaya IP Office (IPO) versions 9.1.0 to 10.1. The PoC triggers an access violation by passing a long string of 'A' characters to the 'open' method, potentially leading to arbitrary code execution.
References (6)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H