Arbitrary code execution - CVE-2016-0913
Published: October 5, 2016 / Updated: October 5, 2016
Vulnerability identifier: #VU762
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2016-0913
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor:
Affected software:
Detailed vulnerability description
The vulnerability allows a remote user to cause arbitrary code execution on the target language.
The weakness is caused by insufficient validation of input. Under the guise of Replication Manager (RM) server attackers can link to the target RM user and trick the victim to load from an SMB share a specially crafted file containing arbitrary code.
Successful exploitation of the vulnerability results in arbitrary code execution on the vulnerable system.
The weakness is caused by insufficient validation of input. Under the guise of Replication Manager (RM) server attackers can link to the target RM user and trick the victim to load from an SMB share a specially crafted file containing arbitrary code.
Successful exploitation of the vulnerability results in arbitrary code execution on the vulnerable system.