CVE-2011-4042
An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to execute arbitrary code by using a crafted HTML document to obtain control of a function pointer.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.43%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to execute arbitrary code by using a crafted HTML document to obtain control of a function pointer.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 6.43% probability · 93th percentile
- CISA KEV
- Not listed
- Affected
- arcinfo/frontvue · arcinfo/pcvue · arcinfo/plantvue
- Source
- cret@cert.org
References
- http://www.pcvuesolutions.com/index.php?option=com_content&view=article&id=244&Itemid=257Vendor Advisory
- http://www.us-cert.gov/control_systems/pdf/ICSA-11-340-01.pdfUS Government Resource
- https://support.pcvuescada.com/index.php?option=com_k2&view=item&id=512&Itemid=440Broken Link
- http://www.pcvuesolutions.com/index.php?option=com_content&view=article&id=244&Itemid=257Vendor Advisory
- http://www.us-cert.gov/control_systems/pdf/ICSA-11-340-01.pdfUS Government Resource
- https://support.pcvuescada.com/index.php?option=com_k2&view=item&id=512&Itemid=440Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.