Siemens FactoryLink 8 CSService Logging Buffer Overflow

0
85

This Metasploit module exploits a vulnerability found on Siemens FactoryLink 8. The vulnerability occurs when CSService.exe processes a CSMSG_ListFiles_REQ message, the user-supplied path first gets converted to ANSI format (CodePage 0), and then gets handled by a logging routine where proper bounds checking is not done, therefore causing a stack-based buffer overflow, and results arbitrary code execution.

Source: Siemens FactoryLink 8 CSService Logging Buffer Overflow