6.8
CVE-2011-2658
- EPSS 2.67%
- Veröffentlicht 26.07.2012 22:55:01
- Zuletzt bearbeitet 16.06.2026 23:31:44
- Erkennungen
The ISList.ISAvi ActiveX control in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.2, 10.3, and 11 SP1 provides access to the mscomct2.ocx file, which allows remote attackers to execute arbitrary code by leveraging unspecified mscomct2 flaws.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Novell ≫ Zenworks Configuration Management Version 10.2
Novell ≫ Zenworks Configuration Management Version 10.3
Novell ≫ Zenworks Configuration Management Version 11 Update sp1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.67% | 0.838 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
http://www.novell.com/support/kb/doc.php?id=7009570
http://www.zerodayinitiative.com/advisories/ZDI-11-317/