cbcvebase.
CVE-2011-4034
published 2011-12-02

CVE-2011-4034: Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and…

PriorityP355critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
13.94%
96.1th percentile
Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service via unspecified vectors.

Affected

8 ranges
VendorProductVersion rangeFixed in
schneider-electriccitecthistorian<= 4.30
schneider-electriccitecthistorian
schneider-electriccitectscada_reports<= 4.10
schneider-electriccitectscada_reports
schneider-electricvijeo_historian<= 4.30
schneider-electricvijeo_historian
schneider-electricvijeo_historian
schneider-electricvijeo_historian

Detection & IOCsextracted from sources · hover to see the quote

filenameTeeChart5.ocx
filenameTeeChart6.ocx
filenameTeeChart7.ocx
filenameTeeChart8.ocx
filenameTeeChart2010.ocx
otherCLSID:B6C10489-FB89-11D4-93C9-006008A7EED4
otherCLSID:536600D3-70FE-4C50-92FB-640F6BFC49AD
otherCLSID:FAB9B41C-87D6-474D-AB7E-F07D78F2422E
otherCLSID:BDEB0088-66F9-4A55-ABD2-0BF8DEEC1196
otherCLSID:FCB4B50A-E3F1-4174-BD18-54C3B3287258
commandAddSeries()
  • Detect instantiation of any of the five vulnerable TeeChart ActiveX CLSIDs in browser or document context; presence of these CLSIDs in registry or memory indicates a vulnerable/exploited control.
  • Monitor for calls to the AddSeries() method on TeeChart ActiveX objects with overly large or negative integer arguments, which triggers the integer overflow leading to arbitrary code execution.
  • The exploit is delivered via browser (drive-by) and targets IE8 with Java support for DEP bypass; monitor for TeeChart OCX files loaded within iexplore.exe process.
  • ·The exploit vector requires social engineering to deliver the malicious content to the victim; purely network-based exploitation without user interaction is not applicable for the TeeChart buffer overflow (CVE-2011-4034).
  • ·Multiple TeeChart OCX versions spanning back to 2001 are affected, so detection rules should cover all five listed CLSIDs/filenames rather than targeting only the latest version.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.