Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

IBM Lotus Notes 'cai' URI and iCal Remote Code Execution Vulnerabilities (Windows)

Information

Severity

Severity

Critical

Family

Family

General

CVSSv2 Base

CVSSv2 Base

9.3

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:M/Au:N/C:C/I:C/A:C

Solution Type

Solution Type

Vendor Patch

Created

Created

13 years ago

Modified

Modified

5 years ago

Summary

This host has IBM Lotus Notes installed and is prone to remote code execution vulnerabilities.

Insight

Insight

The flaws are due to: - An input validation error when processing the '--launcher.library' switch within a 'cai:' URI, which could allow attackers to load a malicious library. - A buffer overflow error related to 'iCal', which could be exploited by attackers to execute arbitrary code.

Affected Software

Affected Software

IBM Lotus Notes Version 8.0.x before 8.0.2 FP6 and 8.5.x before 8.5.1 FP5 on windows

Solution

Solution

Upgrade to IBM Lotus Notes 8.0.2 FP6 or 8.5.1 FP5

Common Vulnerabilities and Exposures (CVE)