← Vulnerability feed

Vulnerability record · CVE-2011-2657 · published 26 July 2012

CVE-2011-2657: Novell ZENworks AdminStudio ActiveX control directory traversal

Novell · Zenworks Configuration Management

The LaunchHelp.HelpLauncher.1 ActiveX control in LaunchHelp.dll, shipped with AdminStudio in Novell ZENworks Configuration Management 10.2, 10.3 and 11 SP1, passes the first argument to LaunchProcess without validating the pathname. A remote attacker can use a crafted pathname to traverse directories and execute arbitrary commands. The flaw matters because it turns a browser-reachable ActiveX control into a command execution primitive on affected Windows hosts.

6.8 CVSS 2.0 Medium EPSS 48% · top 1.2% CWE-22 · Path traversal
6.8CVSS 2.0 base score
48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in the LaunchProcess function in the LaunchHelp.HelpLauncher.1 ActiveX control in LaunchHelp.dll in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.2, 10.3, and 11 SP1 allows remote attackers to execute arbitrary commands via a pathname in the first argument.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityRemote command execution with a public exploit and very high EPSS, tempered by the need for user interaction and the age of the affected product.

What it is

The LaunchHelp.HelpLauncher.1 ActiveX control in LaunchHelp.dll, shipped with AdminStudio in Novell ZENworks Configuration Management 10.2, 10.3 and 11 SP1, passes the first argument to LaunchProcess without validating the pathname. A remote attacker can use a crafted pathname to traverse directories and execute arbitrary commands. The flaw matters because it turns a browser-reachable ActiveX control into a command execution primitive on affected Windows hosts.

Impact

An attacker who can get the control instantiated gains arbitrary command execution in the context of the user running the browser or host process. That can lead to full compromise of the workstation and any credentials or management access it holds.

Attack surface

Reached remotely over the network through the ActiveX control, typically by luring a user to a malicious or compromised web page that instantiates LaunchHelp.HelpLauncher.1. No authentication is required, but the CVSS vector marks access complexity as medium and the attack depends on the victim's browser loading the control, so user interaction is effectively required.

Exploitation

Not listed in CISA KEV and no ransomware association is documented, but a public Exploit-DB entry exists and EPSS is very high (0.484, 98.8th percentile), indicating substantial observed or expected exploitation activity.

What to do

  • Apply the Novell patch referenced in vendor advisory KB 7009570 for ZENworks Configuration Management 10.2, 10.3 and 11 SP1.
  • If patching is delayed, disable or kill-bit the LaunchHelp.HelpLauncher.1 ActiveX control in Internet Explorer and block its CLSID via Group Policy.
  • Restrict browser use of ActiveX controls and enforce allow-listing so untrusted sites cannot instantiate local controls.
  • Limit user privileges on ZENworks-managed endpoints so command execution does not yield administrative rights.
  • Monitor vendor advisories for updated guidance if the affected versions are still in service.

Detection

  • Hunt for processes spawned by browser or host processes that load LaunchHelp.dll, especially with command-line arguments containing traversal sequences such as ..\ or ../.
  • Audit endpoint logs and EDR telemetry for LaunchHelp.dll or the LaunchHelp.HelpLauncher.1 CLSID being loaded outside expected AdminStudio/ZENworks workflows.
  • Review web proxy and DNS logs for users visiting sites known to host the Exploit-DB 19718 proof-of-concept or similar ActiveX exploit pages.
  • Check for unexpected child processes (cmd.exe, powershell.exe, wscript.exe) originating from iexplore.exe or other processes hosting the control.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-2657 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-7169GNU Bash environment variable function parsing command injection (Shellshock variant)GNU Bash through 4.3 bash43-025 processes trailing strings after malformed function definitions in environment variable values, allowing command inje…KEVEPSS 100%analysed9.8CVE-2014-6271GNU Bash environment variable command injection (ShellShock)GNU Bash through 4.3 processes trailing strings after function definitions in environment variable values, allowing injected commands to run when Bas…KEVEPSS 100%analysed10.0CVE-2015-0779Novell ZENworks Configuration Management UploadServlet path traversal RCEUploadServlet in Novell ZENworks Configuration Management 10 and 11 before 11.3.2 is vulnerable to directory traversal via the uid parameter. A craft…EPSS 74%analysed10.0CVE-2010-5324Novell ZENworks Configuration Management UploadServlet path traversal RCEUploadServlet in the Remote Management component of Novell ZENworks Configuration Management 10 before 10.3 is vulnerable to directory traversal via …EPSS 72%analysed10.0CVE-2010-5323Novell zenworks configuration management path traversal vulnerabilityDirectory traversal vulnerability in UploadServlet in the Remote Management component in Novell ZENworks Configuration Management (ZCM) 10 before 10.…EPSS 14%10.0CVE-2013-6345Novell zenworks configuration management vulnerabilityUnspecified vulnerability in the ZCC page in Novell ZENworks Configuration Management (ZCM) before 11.2.4 has unknown impact and attack vectors relat…EPSS 1.5%10.0CVE-2013-1080Novell ZENworks ZCM web server auth bypass enabling traversal and code executionThe web server in Novell ZENworks Configuration Management 10.3 and 11.2 before 11.2.4 fails to properly authenticate requests to zenworks/jsp/index.…EPSS 77%analysed10.0CVE-2011-3175Novell ZENworks Preboot Service stack buffer overflow via opcode 0x6cThe Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1a contains a stack-based buffer overflow (CWE-119) triggered by an…EPSS 66%analysed

Source: NIST National Vulnerability Database (record CVE-2011-2657), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.