Remote Code Execution Vulnerability in Dell System Lite Scanner ActiveX Control
CVE-2011-0330

Currently unrated

Key Information:

Vendor
Dell
Vendor
CVE Published:
21 February 2011

Summary

The Dell System Lite Scanner ActiveX control in DellSystemLite.ocx version 1.0.0.0 contains a vulnerability that fails to properly enforce restrictions on the WMIAttributesOfInterest property. This oversight allows attackers to execute arbitrary WMI Query Language (WQL) statements by providing crafted input values. As a result, this invites the potential for remote attackers to gain unauthorized access to sensitive information regarding installed software on the affected system, leading to further exploitation possibilities.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.