Arbitrary code execution - CVE-2016-0913

 

Arbitrary code execution - CVE-2016-0913

Published: October 5, 2016 / Updated: October 5, 2016


Vulnerability identifier: #VU762
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2016-0913
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor:
Affected software:

Detailed vulnerability description

The vulnerability allows a remote user to cause arbitrary code execution on the target language.
The weakness is caused by insufficient validation of input. Under the guise of Replication Manager (RM) server attackers can link to the target RM user and trick the victim to load from an SMB share a specially crafted file containing arbitrary code.
Successful exploitation of the vulnerability results in arbitrary code execution on the vulnerable system.



How to mitigate CVE-2016-0913


Sources