CVE-2013-3075 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 10.8% (pctl 96)
Patch early
A public exploit exists.
Description
Multiple buffer overflows in ActUWzd.dll 1.0.0.1 in Mitsubishi MX Component 3, as distributed in Citect CitectFacilities 7.10 and CitectScada 7.10r1, allow remote attackers to execute arbitrary code via a long string, as demonstrated by a long WzTitle property value to a certain ActiveX control.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 10.77% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2013-04-19 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| mitsubishi-automation | mitsubishi mx component |
| schneider-electric | citectfacilities |
| schneider-electric | citectscada |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Mitsubishi MX ActiveX Component 3 - 'ActUWzd.dll' 'WzTitle' Remote Heap Spray | 2013-03-25 |
→ the Explorer · watch your stack · NVD