Description
COMMAX UMS Client ActiveX Control 1.7.0.2 contains a heap-based buffer overflow vulnerability that allows attackers to execute arbitrary code by providing excessively long string arrays through multiple functions. Attackers can exploit improper boundary validation in CNC_Ctrl.dll to cause heap corruption and potentially gain system-level access.
Problem types
Product status
1.7.0.2
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.exploit-db.com/exploits/50232 (ExploitDB-50232)
www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5664.php (Zero Science Lab Disclosure (ZSL-2021-5664))
www.commax.com (Reference)
www.vulncheck.com/...ntrol-cnc-ctrl-dll-heap-buffer-overflow (VulnCheck Advisory: CNC_Ctrl DllUnregisterServer Access Violation)