← Vulnerability feed

Vulnerability record · CVE-2011-0340 · published 4 May 2011

CVE-2011-0340: Advantech studio memory buffer overflow vulnerability

Advantech · Advantech Studio

Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distributed in Advantech Studio 6.1 SP6 61.6.01.05, InduSoft Web Studio before 7.0+SP1, and InduSoft Thin Client 7.0, allow remote attackers to execute arbitrary code via a long (1) InternationalOrder, (2) InternationalSeparator, or (3) LogFileName property value; or (4) a long bstrFileName argument to the OpenScreen method.

9.3 CVSS 2.0 High EPSS 32% · top 1.7% CWE-119 · Memory buffer overflow
9.3CVSS 2.0 base score
32%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
22References
16 Jun 2026Last modified by NVD

Description

Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distributed in Advantech Studio 6.1 SP6 61.6.01.05, InduSoft Web Studio before 7.0+SP1, and InduSoft Thin Client 7.0, allow remote attackers to execute arbitrary code via a long (1) InternationalOrder, (2) InternationalSeparator, or (3) LogFileName property value; or (4) a long bstrFileName argument to the OpenScreen method.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-0340 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-0780InduSoft Web Studio NTWebServer path traversal exposes admin passwordsNTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 is vulnerable to directory traversal, allowing remote attackers to read administrative pass…KEVEPSS 75%analysed10.0CVE-2011-4051InduSoft Web Studio CEServer missing authentication allows remote code executionCEServer.exe in the Remote Agent module of InduSoft Web Studio 6.1 and 7.0 does not require authentication. A remote attacker can reach the service a…EPSS 69%analysed10.0CVE-2011-0342Indusoft web studio memory buffer overflow vulnerabilityMultiple buffer overflows in the InduSoft ISSymbol ActiveX control in ISSymbol.ocx 301.1104.601.0 in InduSoft Web Studio 7.0B2 hotfix 7.0.01.04 allow…EPSS 5.9%10.0CVE-2011-1900Indusoft web studio path traversal vulnerabilityDirectory traversal vulnerability in NTWebServer in InduSoft Web Studio 6.1 and 7.x before 7.0+Patch 1 allows remote attackers to execute arbitrary c…EPSS 32%10.0CVE-2011-0488Advantech studio memory buffer overflow vulnerabilityStack-based buffer overflow in NTWebServer.exe in the test web service in InduSoft NTWebServer, as distributed in Advantech Studio 6.1 and InduSoft W…EPSS 8.6%9.8CVE-2018-8840Indusoft web studio stack-based buffer overflow vulnerabilityA remote attacker could send a carefully crafted packet in InduSoft Web Studio v8.1 and prior versions, and/or InTouch Machine Edition 2017 v8.1 and …EPSS 8.3%9.3CVE-2011-4052Indusoft web studio memory buffer overflow vulnerabilityStack-based buffer overflow in CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 allows remote att…EPSS 5.7%7.8CVE-2013-1627Advantech studio path traversal vulnerabilityAbsolute path traversal vulnerability in NTWebServer.exe in Indusoft Studio 7.0 and earlier and Advantech Studio 7.0 and earlier allows remote attack…EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2011-0340), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.