Vulnerabilities > CVE-2012-0549 - Unspecified vulnerability in Oracle Supply Chain products Suite 20.1.1

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
oracle
exploit available
metasploit

Summary

Unspecified vulnerability in the Oracle AutoVue Office component in Oracle Supply Chain Products Suite 20.1.1 allows remote attackers to affect confidentiality, integrity, and availability, related to Desktop API.

Vulnerable Configurations

Part Description Count
Application
Oracle
1

Exploit-Db

descriptionOracle AutoVue ActiveX Control SetMarkupMode Buffer Overflow. CVE-2012-0549. Remote exploit for windows platform
idEDB-ID:20297
last seen2016-02-02
modified2012-08-06
published2012-08-06
reportermetasploit
sourcehttps://www.exploit-db.com/download/20297/
titleOracle AutoVue ActiveX Control SetMarkupMode Buffer Overflow

Metasploit

descriptionThis module exploits a vulnerability found in the AutoVue.ocx ActiveX control. The vulnerability, due to the insecure usage of an strcpy like function in the SetMarkupMode method, when handling a specially crafted sMarkup argument, allows to trigger a stack based buffer overflow which leads to code execution under the context of the user visiting a malicious web page. The module has been successfully tested against Oracle AutoVue Desktop Version 20.0.0 (AutoVue.ocx 20.0.0.7330) on IE 6, 7, 8 and 9 (Java 6 needed to DEP and ASLR bypass).
idMSF:EXPLOIT/WINDOWS/BROWSER/ORACLE_AUTOVUE_SETMARKUPMODE
last seen2020-03-19
modified2020-02-18
published2012-08-05
references
reporterRapid7
sourcehttps://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/browser/oracle_autovue_setmarkupmode.rb
titleOracle AutoVue ActiveX Control SetMarkupMode Buffer Overflow

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/115324/oracle_autovue_setmarkupmode.rb.txt
idPACKETSTORM:115324
last seen2016-12-05
published2012-08-07
reporterjuan vazquez
sourcehttps://packetstormsecurity.com/files/115324/Oracle-AutoVue-ActiveX-Control-SetMarkupMode-Buffer-Overflow.html
titleOracle AutoVue ActiveX Control SetMarkupMode Buffer Overflow

Saint

bid53077
descriptionOracle AutoVue SetMarkupMode ActiveX Overflow
osvdb81439
titleoracle_autovue_setmarkupmode_activex
typeclient