Vulnerability Description
EmTec ZOC through 8.02.4 allows remote servers to cause a denial of service (Windows GUI hang) by telling the ZOC window to change its title repeatedly at high speed, which results in many SetWindowTextA or SetWindowTextW calls. In other words, it does not implement a usleep or similar delay upon processing a title change.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Emtec | Zoc | <= 8.02.4 |
References
- http://www.emtec.com/downloads/zoc/zoc_changes.txtRelease NotesVendor Advisory
- https://pastebin.com/0xhrDvW0Third Party Advisory
- http://www.emtec.com/downloads/zoc/zoc_changes.txtRelease NotesVendor Advisory
- https://pastebin.com/0xhrDvW0Third Party Advisory
FAQ
What is CVE-2021-32198?
CVE-2021-32198 is a vulnerability with a CVSS score of 9.8 (CRITICAL). EmTec ZOC through 8.02.4 allows remote servers to cause a denial of service (Windows GUI hang) by telling the ZOC window to change its title repeatedly at high speed, which results in many SetWindowTe...
How severe is CVE-2021-32198?
CVE-2021-32198 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-32198?
Check the references section above for vendor advisories and patch information. Affected products include: Emtec Zoc.