CVE-2017-12969
Buffer overflow in the ViewerCtrlLib.ViewerCtrl ActiveX control in Avaya IP Office Contact Center before 10.1.1 allows remote attackers to cause a denial of service (heap corruption and crash) or execute arbitrary code via a long string to the open…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.1%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in the ViewerCtrlLib.ViewerCtrl ActiveX control in Avaya IP Office Contact Center before 10.1.1 allows remote attackers to cause a denial of service (heap corruption and crash) or execute arbitrary code via a long string to the open method.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 10.08% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- avaya/ip office contact center
- Source
- cve@mitre.org
References
- http://downloads.avaya.com/css/P8/documents/101044091Vendor Advisory
- http://hyp3rlinx.altervista.org/advisories/AVAYA-OFFICE-IP-%28IPO%29-v9.1.0-10.1-VIEWERCTRL-ACTIVE-X-BUFFER-OVERFLOW-0DAY.txt
- http://packetstormsecurity.com/files/144882/Avaya-IP-Office-IPO-10.1-Active-X-Buffer-Overflow.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2017/Nov/17Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/101667Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/43120/Third Party Advisory, VDB Entry
- http://downloads.avaya.com/css/P8/documents/101044091Vendor Advisory
- http://hyp3rlinx.altervista.org/advisories/AVAYA-OFFICE-IP-%28IPO%29-v9.1.0-10.1-VIEWERCTRL-ACTIVE-X-BUFFER-OVERFLOW-0DAY.txt
- http://packetstormsecurity.com/files/144882/Avaya-IP-Office-IPO-10.1-Active-X-Buffer-Overflow.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2017/Nov/17Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/101667Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/43120/Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.