Description
EmTec ZOC through 8.02.4 allows remote servers to cause a denial of service (Windows GUI hang) by telling the ZOC window to change its title repeatedly at high speed, which results in many SetWindowTextA or SetWindowTextW calls. In other words, it does not implement a usleep or similar delay upon processing a title change.
References
http://www.emtec.com/downloads/zoc/zoc_changes.txt
Release NotesVendor Advisory
Third Party Advisory
http://www.emtec.com/downloads/zoc/zoc_changes.txt
Release NotesVendor Advisory
Third Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8 · Critical
Information
Source identifier
Vulnerability status
Modified
Published
2021-06-06T10:15:07.380Z
4 years agoLast modified
2024-11-21T05:06:53.980Z
1 year ago