E15-93y01
CVSS:
6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P)
False Positive:
f
Variants:
2
Year:
2015
Description
This strike exploits a memory corruption vulnerability in Schneider Electric ProClima F1BookView ActiveX Control. Specifically the vulnerability in how the Rule and Text parameters are processed as iteration counters in a loop. The loop reads these 2 parameters and calculates their length. Then this data is read onto the stack and if x or y is larger than the amount of data between the current memory location and the end of the stack, a memory access violation occurs.