Control Center PRO 6.2.9 - Local Stack Based BufferOverflow
Vulnerability Description
Control Center PRO 6.2.9 contains a stack-based buffer overflow vulnerability in the user creation module's username field that allows attackers to overwrite Structured Exception Handler (SEH). Attackers can craft a malicious payload exceeding 664 bytes to inject shellcode and potentially execute arbitrary code on vulnerable Windows systems.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-25357
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Samir sanchez garnica @sasaga92
References
- https://www.exploit-db.com/exploits/47645
- http://www.webgateinc.com/wgi/eng/products/list.php?ec_idx1=P610
- http://www.webgateinc.com/wgi/eng/products/list.php?ec_idx1=P610&ptype=view&page=&p_idx=90&tab=download&#tabdown
- https://www.vulncheck.com/advisories/control-center-pro-local-stack-based-bufferoverflow
Affected Vendor
WEBGATE Inc.
View all reports →