Buffer Overflow Vulnerability in COMMAX WebViewer ActiveX Control
CVE-2021-47719
Key Information:
- Vendor
Commax Co., Ltd.
- Vendor
- CVE Published:
- 9 December 2025
Badges
What is CVE-2021-47719?
The COMMAX WebViewer ActiveX Control version 2.1.4.5 is prone to a buffer overflow vulnerability that arises when handling excessively long string arrays through multiple functions. This flaw allows attackers to trigger boundary errors within the Commax_WebViewer.ocx module, potentially leading to arbitrary code execution. Exploitation of this vulnerability can expose systems to significant risks, allowing unauthorized actions and access.
Affected Version(s)
COMMAX WebViewer ActiveX Control 2.1.4.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
