CVE-2018-6911
CRITICALAdvantech WebAccess 8.3.0 - Remote Code Execution via VBWinExec Command Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-6911. PoCs published by Nassim Asrir.
AI-analyzed exploit summary This exploit leverages a vulnerable function (VBWinExec) in Advantech WebAccess Node 8.3.0's AspVBObj.dll to execute arbitrary OS commands via a single argument. The PoC demonstrates remote code execution by launching calc.exe through an ActiveX object.
Description
The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS commands via a single argument (aka the command parameter).
Exploits (1)
This exploit leverages a vulnerable function (VBWinExec) in Advantech WebAccess Node 8.3.0's AspVBObj.dll to execute arbitrary OS commands via a single argument. The PoC demonstrates remote code execution by launching calc.exe through an ActiveX object.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H