|CVSS SCORE||7.5, (AV:N/AC:L/Au:N/C:P/I:P/A:P)|
|TREND MICRO CUSTOMER PROTECTION||Trend Micro TippingPoint IPS customers are protected against this vulnerability by Digital Vaccine protection filter ID 16855. For further product information on the TippingPoint IPS: http://www.tippingpoint.com|
The specific flaw exists within the HWOPOSSCANNER.ocx. The control does not check the length of an attacker-supplied string to the Open method before copying it into a fixed length buffer on the stack. This allows an attacker to execute arbitrary code in the context of the browser process.
Honeywell has issued an update to correct this vulnerability. More details can be found at:
|CREDIT||Ariele Caltabiano (kimiya)