Description
Control Center PRO 6.2.9 contains a stack-based buffer overflow vulnerability in the user creation module's username field that allows attackers to overwrite Structured Exception Handler (SEH). Attackers can craft a malicious payload exceeding 664 bytes to inject shellcode and potentially execute arbitrary code on vulnerable Windows systems.
Problem types
Product status
Credits
Samir sanchez garnica @sasaga92
References
www.exploit-db.com/exploits/47645 (ExploitDB-47645)
www.webgateinc.com/wgi/eng/products/list.php?ec_idx1=P610 (Vendor Homepage)
www.webgateinc.com/...type=view&page=&p_idx=90&tab=download& (Software Download Page)
www.vulncheck.com/...er-pro-local-stack-based-bufferoverflow (VulnCheck Advisory: Control Center PRO 6.2.9 - Local Stack Based BufferOverflow)