Skip to main content

Novell ZENworks Configuration Management AdminStudio ActiveX Controls Vulnerabilities

Last Update Date: 20 Oct 2011 11:30 Release Date: 20 Oct 2011 5841 Views

RISK: High Risk

TYPE: Operating Systems - Networks OS

TYPE: Networks OS

Multiple vulnerabilities have been reported in Novell ZENworks Configuration Management, which can be exploited by malicious people to compromise a user's system.

  1. An unspecified error in the "DoFindReplace()" method within the SIGrid.Grid.1 ActiveX control can be exploited via certain input passed in the "bstrReplaceText" parameter.
  2. An unspecified error exists in the Antique ActiveX control, and the help.Dall ActiveX control related to the Launch process functionality.

Successful exploitation of the vulnerabilities may allow execution of arbitrary code.


Impact

  • Remote Code Execution

System / Technologies affected

  • Novell ZENworks Configuration Management 10.x
  • Novell ZENworks Configuration Management 11.x

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier

  • No CVE information is available

Source


Related Link