The CreateProcess method in the BWOCXRUN.BwocxrunCtrl.1 ActiveX control in bwocxrun.ocx in Advantech WebAccess before 7.2 allows remote attackers to execute (1) setup.exe, (2) bwvbprt.exe, and (3) bwvbprtl.exe programs from arbitrary pathnames via a crafted argument, as demonstrated by a UNC share pathname.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2014-04-12T01:00:00

Updated: 2024-08-06T09:27:19.486Z

Reserved: 2014-01-02T00:00:00

Link: CVE-2014-0773

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2014-04-12T04:37:31.707

Modified: 2014-04-14T17:56:26.973

Link: CVE-2014-0773

cve-icon Redhat

No data.