CVE-2015-2094 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 14% (pctl 96)
Patch early
A public exploit exists.
Description
Stack-based buffer overflow in the WESPPlayback.WESPPlaybackCtrl.1 control in WebGate WinRDS allows remote attackers to execute arbitrary code via unspecified vectors to the (1) PrintSiteImage, (2) PlaySiteAllChannel, (3) StopSiteAllChannel, or (4) SaveSiteImage function.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 14.01% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2015-03-09 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| webgateinc | winrds |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | WebGate WinRDS 2.0.8 - PlaySiteAllChannel Stack Buffer Overflow | 2015-04-02 |
| exploit-db | WebGate WinRDS 2.0.8 - StopSiteAllChannel Stack Overflow | 2015-03-27 |
References
- http://packetstormsecurity.com/files/131069/WebGate-WinRDS-2.0.8-StopSiteAllChannel-Stack-Overflow.html
- http://www.osvdb.org/118905
- http://www.osvdb.org/118906
- http://www.osvdb.org/118907
- http://www.osvdb.org/118908
- http://www.securityfocus.com/bid/72841
- http://www.zerodayinitiative.com/advisories/ZDI-15-071/
- http://www.zerodayinitiative.com/advisories/ZDI-15-072/
- http://www.zerodayinitiative.com/advisories/ZDI-15-073/
- http://www.zerodayinitiative.com/advisories/ZDI-15-074/
- https://www.exploit-db.com/exploits/36517/
- http://packetstormsecurity.com/files/131069/WebGate-WinRDS-2.0.8-StopSiteAllChannel-Stack-Overflow.html
- http://www.osvdb.org/118905
- http://www.osvdb.org/118906
- http://www.osvdb.org/118907
- http://www.osvdb.org/118908
- http://www.securityfocus.com/bid/72841
- http://www.zerodayinitiative.com/advisories/ZDI-15-071/
- http://www.zerodayinitiative.com/advisories/ZDI-15-072/
- http://www.zerodayinitiative.com/advisories/ZDI-15-073/
→ the Explorer · watch your stack · NVD