IBM SPSS SamplePower 3.0 < 3.0 FP 1 Multiple ActiveX Controls Arbitrary Code Execution

High Nessus Plugin ID 66473


The remote host has multiple ActiveX controls with code execution vulnerabilities.


The remote install of IBM SPSS SamplePower has a vulnerable version of one or more ActiveX controls installed. 'Vsflex8l.ocx', 'c1sizer.ocx', 'vsflex7l .ocx', and 'olch2x32.ocx' ActiveX controls have unspecified arbitrary code execution vulnerabilities, which can be exploited by tricking a user into opening a specially crafted web page.


Upgrade to IBM SPSS SamplePower 3.0 FP 1 or higher.

See Also

Plugin Details

Severity: High

ID: 66473

File Name: ibm_spss_sample_power_activex.nasl

Version: $Revision: 1.10 $

Type: remote

Agent: windows

Family: Windows

Published: 2013/05/16

Modified: 2017/07/08

Dependencies: 66472

Risk Information

Risk Factor: High


Base Score: 9.3

Temporal Score: 7.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:POC/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:ibm:spss_samplepower

Required KB Items: SMB/ibm_spss_samplepower/Version

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2013/04/26

Vulnerability Publication Date: 2013/05/26

Exploitable With

CANVAS (D2ExploitPack)

Core Impact

Metasploit (IBM SPSS SamplePower C1Tab ActiveX Heap Overflow)

Reference Information

CVE: CVE-2012-5945, CVE-2012-5946, CVE-2012-5947, CVE-2013-0593

BID: 59527, 59556, 59557, 59559

OSVDB: 92814, 92844, 92845, 92846