IBM Lotus iNotes Upload Module ActiveX Control Attachment_Times() Method Buffer Overflow

High Nessus Plugin ID 59685


The remote Windows host has an ActiveX control that is affected by a buffer overflow vulnerability.


The Lotus iNotes Upload Module ActiveX Control is installed on the remote Windows host. The installed version of the control is affected by a buffer overflow vulnerability in the Attachment_Times() method.
By tricking a victim into visiting a specially crafted page, an attacker may be able to execute arbitrary code on the host.


Either set the kill bit for the control or see the vendor's advisory for an updated control.

See Also

Plugin Details

Severity: High

ID: 59685

File Name: lotus_notes_upload_activex_bof.nasl

Version: $Revision: 1.10 $

Type: local

Agent: windows

Family: Windows

Published: 2012/06/19

Modified: 2017/08/31

Dependencies: 13855

Risk Information

Risk Factor: High


Base Score: 9.3

Temporal Score: 7.7

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:F/RL:OF/RC:ND

Vulnerability Information

CPE: cpe:/a:ibm:lotus_notes

Required KB Items: SMB/Registry/Enumerated

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2012/05/31

Vulnerability Publication Date: 2012/05/31

Exploitable With

Core Impact

Metasploit (IBM Lotus iNotes dwa85W ActiveX Buffer Overflow)

Reference Information

CVE: CVE-2012-2175

BID: 53879

OSVDB: 82755