CVE-2011-4052
Last modified
CVE-2011-4052 is a vulnerability of currently unknown severity. Stack-based buffer overflow in CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 allows remote attackers to execute arbitrary code via a crafted 0x15 (aka Remove File) operation for a file with a long name.. EPSS estimates a 5.94% chance of exploitation in the next 30 days.
Description
Stack-based buffer overflow in CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 allows remote attackers to execute arbitrary code via a crafted 0x15 (aka Remove File) operation for a file with a long name.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Indusoft | Web Studio | 6.1 |
| Indusoft | Web Studio | 7.0 |
References
- http://www.us-cert.gov/control_systems/pdf/ICSA-11-319-01.pdfUS Government Resource
- http://www.us-cert.gov/control_systems/pdf/ICSA-11-319-01.pdfUS Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-4052?
How severe is CVE-2011-4052?
How do I fix CVE-2011-4052?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2011
- CVE-2011-4045Buffer overflow in an unspecified ActiveX control in aipgctl…
- CVE-2011-4046The Dell KACE K2000 System Deployment Appliance stores the r…
- CVE-2011-4047The Dell KACE K2000 System Deployment Appliance allows remot…
- CVE-2011-4048The Dell KACE K2000 System Deployment Appliance has a defaul…
- CVE-2011-4050Buffer overflow in 7-Technologies (7T) Interactive Graphical…
- CVE-2011-4051CEServer.exe in the CEServer component in the Remote Agent m…
- CVE-2011-4053Untrusted search path vulnerability in 7-Technologies (7T) I…
- CVE-2011-4054Cross-site scripting (XSS) vulnerability in login.fcc in CA …
- CVE-2011-4055Buffer overflow in the WebClient ActiveX control in Siemens …
- CVE-2011-4056An unspecified ActiveX control in ActBar.ocx in Siemens Tecn…
- CVE-2011-4057Wibu-Systems AG CodeMeter Runtime 4.30c, 4.10b, and possibly…
- CVE-2011-4060The runtime linker in QNX Neutrino RTOS 6.5.0 before Service…
Are you affected by CVE-2011-4052?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
