CVE-2011-0517
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 40%
from disclosure to weapon0 days
Published on NVDJan 20
1st PoCJan 14
metasploitJan 13
exploitation probability
40%top 2% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
Stack-based buffer overflow in Sielco Sistemi Winlog Pro 2.07.00 and earlier, when Run TCP/IP server is enabled, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a crafted 0x02 opcode to TCP port 46823.
Affected products
n/a · n/apublic PoCs found — 3
cve_referencewww.exploit-db.com/exploits/15992unverifiedexploitdbwww.exploit-db.com/exploits/15992unverifiedexploitdbwww.exploit-db.com/exploits/17430unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://aluigi.org/adv/winlog_1-adv.txthttp://osvdb.org/70418http://secunia.com/advisories/42894http://securityreason.com/securityalert/8280https://exchange.xforce.ibmcloud.com/vulnerabilities/64716http://www.exploit-db.com/exploits/15992http://www.kb.cert.org/vuls/id/496040http://www.securityfocus.com/bid/45813http://www.us-cert.gov/control_systems/pdf/ICSA-11-017-02.pdfhttp://www.vupen.com/english/advisories/2011/0126