The Dell DellSystemLite.Scanner ActiveX control in DellSystemLite.ocx 1.0.0.0 does not properly restrict the values of the WMIAttributesOfInterest property, which allows remote attackers to execute arbitrary WMI Query Language (WQL) statements via a crafted value, as demonstrated by a value that triggers disclosure of information about installed software.
Advisories
Source ID Title
EUVD EUVD EUVD-2011-0356 The Dell DellSystemLite.Scanner ActiveX control in DellSystemLite.ocx 1.0.0.0 does not properly restrict the values of the WMIAttributesOfInterest property, which allows remote attackers to execute arbitrary WMI Query Language (WQL) statements via a crafted value, as demonstrated by a value that triggers disclosure of information about installed software.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: flexera

Published:

Updated: 2024-08-06T21:51:08.031Z

Reserved: 2011-01-06T00:00:00

Link: CVE-2011-0330

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2011-02-21T18:00:01.223

Modified: 2025-04-11T00:51:21.963

Link: CVE-2011-0330

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses