peter bassill · operator
$ cve CVE-2011-4051 JSON

CVE-2011-4051 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 69.1% (pctl 99)

Patch early

A public exploit exists.

Description

CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 does not require authentication, which allows remote attackers to execute arbitrary code via vectors related to creation of a file, loading a DLL, and process control.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS69.1% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploityes
Published2011-12-05
Last modified2026-06-16

Affected (1)

VendorProduct
indusoftweb studio

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD