CVE-2011-4043 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 7.4% (pctl 94)
Patch early
A public exploit exists.
Description
Integer overflow in an unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to execute arbitrary code via a large value for an integer parameter, leading to a buffer overflow.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 7.42% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-189 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2012-04-03 |
| Last modified | 2026-07-09 |
Affected (3)
| Vendor | Product |
|---|---|
| arcinfo | frontvue |
| arcinfo | pcvue |
| arcinfo | plantvue |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | PcVue 10.0 - Multiple Vulnerabilities | 2011-09-27 |
References
- http://www.pcvuesolutions.com/index.php?option=com_content&view=article&id=244&Itemid=257
- http://www.us-cert.gov/control_systems/pdf/ICSA-11-340-01.pdf
- https://support.pcvuescada.com/index.php?option=com_k2&view=item&id=512&Itemid=440
- http://www.pcvuesolutions.com/index.php?option=com_content&view=article&id=244&Itemid=257
- http://www.us-cert.gov/control_systems/pdf/ICSA-11-340-01.pdf
- https://support.pcvuescada.com/index.php?option=com_k2&view=item&id=512&Itemid=440
→ the Explorer · watch your stack · NVD