CVE-2011-2657 EXPLOIT
6.8
MEDIUM · CVSS 2.0 · EPSS 48.4% (pctl 99)
Patch early
A public exploit exists.
Description
Directory traversal vulnerability in the LaunchProcess function in the LaunchHelp.HelpLauncher.1 ActiveX control in LaunchHelp.dll in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.2, 10.3, and 11 SP1 allows remote attackers to execute arbitrary commands via a pathname in the first argument.
Scoring
| CVSS | 6.8 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
| EPSS | 48.37% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2012-07-26 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| novell | zenworks configuration management |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | AdminStudio - 'LaunchHelp.dll' ActiveX Arbitrary Code Execution (Metasploit) | 2012-07-11 |
References
→ the Explorer · watch your stack · NVD