Remote Code Execution Vulnerability in IBM SPSS SamplePower ActiveX Control
CVE-2013-6724

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
1 February 2014

Summary

A vulnerability exists in the vsflex8l ActiveX control within IBM SPSS SamplePower version 3.0.1 and earlier. This flaw may allow remote attackers to execute arbitrary code by supplying a specially crafted value to the ComboList property. Unpatched installations of this software are at risk, exposing users to potential exploit scenarios that can lead to unauthorized execution of commands on the host system.

References

EPSS Score

5% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.