Description
COMMAX WebViewer ActiveX Control 2.1.4.5 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by providing excessively long string arrays through multiple functions. Attackers can exploit boundary errors in Commax_WebViewer.ocx to cause buffer overflow conditions and potentially gain code execution.
Problem types
Product status
2.1.4.5
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.exploit-db.com/exploits/50231 (ExploitDB-50231)
www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5663.php (Zero Science Lab Disclosure (ZSL-2021-5663))
www.commax.com (Reference)
www.vulncheck.com/...ol-commax-webviewer-ocx-buffer-overflow (VulnCheck Advisory: CNC_Ctrl DllUnregisterServer f5501 Access Violation)