1000
VMScore

CVE-2016-5228

Published: 03/07/2016 Updated: 07/11/2023
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Stack-based buffer overflow in the PlayMacro function in ObjectXMacro.ObjectXMacro in WdMacCtl.ocx in Micro Focus Rumba 9.x prior to 9.3 HF 11997 and 9.4.x prior to 9.4 HF 12815 allows remote malicious users to execute arbitrary code via a long MacroName argument. NOTE: some references mention CVE-2016-5226 but that is not a correct ID for any Rumba vulnerability.

Vulnerable Product Search on Vulmon Subscribe to Product

microfocus rumba 9.4

Exploits

# Exploit Title: Micro Focus Rumba <= 93 ActiveX Stack-based buffer overflow # Date: 29-10-2016 # Exploit Author: Umit Aksu # Vendor Homepage: communitymicrofocuscom/microfocus/mainframe_solutions/rumba/w/knowledge_base/28600micro-focus-rumba-9-x-security-updateaspx # Software Link: nadownloadsmicrofocuscom/epd/product_downl ...