peter bassill · operator
$ cve CVE-2011-2657 JSON

CVE-2011-2657 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 48.4% (pctl 99)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in the LaunchProcess function in the LaunchHelp.HelpLauncher.1 ActiveX control in LaunchHelp.dll in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.2, 10.3, and 11 SP1 allows remote attackers to execute arbitrary commands via a pathname in the first argument.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS48.37% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2012-07-26
Last modified2026-06-16

Affected (1)

VendorProduct
novellzenworks configuration management

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD