CVE ID | CVE-2014-3913 |
CVSS SCORE | 10.0, AV:N/AC:L/Au:N/C:C/I:C/A:C |
AFFECTED VENDORS |
Ericom |
AFFECTED PRODUCTS |
AccessNow Server |
VULNERABILITY DETAILS |
The specific flaw exists in the way AccessServer32.exe handles requests for non-existent files. AccessServer32.exe performs insufficient bounds checking on user-supplied data which results in stack corruption. An attacker can exploit this condition to achieve remote code execution as SYSTEM. |
ADDITIONAL DETAILS |
Vendor Contact Timeline: Mitigation: Vendor Patch: http://www.ericom.com/security-ERM-2014-610.asp
|
DISCLOSURE TIMELINE |
|
CREDIT | Anonymous |