Vulnerability Description
COMMAX UMS Client ActiveX Control 1.7.0.2 contains a heap-based buffer overflow vulnerability that allows attackers to execute arbitrary code by providing excessively long string arrays through multiple functions. Attackers can exploit improper boundary validation in CNC_Ctrl.dll to cause heap corruption and potentially gain system-level access.
Related Weaknesses (CWE)
References
- https://www.commax.com
- https://www.exploit-db.com/exploits/50232
- https://www.vulncheck.com/advisories/commax-ums-client-activex-control-cnc-ctrl-
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5664.php
FAQ
What is CVE-2021-47705?
CVE-2021-47705 is a documented vulnerability. COMMAX UMS Client ActiveX Control 1.7.0.2 contains a heap-based buffer overflow vulnerability that allows attackers to execute arbitrary code by providing excessively long string arrays through multip...
How severe is CVE-2021-47705?
CVSS scoring is not yet available for CVE-2021-47705. Check NVD for updates.
Is there a patch for CVE-2021-47705?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.