Vulnerability record · CVE-2011-2657 · published 26 July 2012
CVE-2011-2657: Novell ZENworks AdminStudio ActiveX control directory traversal
Novell · Zenworks Configuration Management
The LaunchHelp.HelpLauncher.1 ActiveX control in LaunchHelp.dll, shipped with AdminStudio in Novell ZENworks Configuration Management 10.2, 10.3 and 11 SP1, passes the first argument to LaunchProcess without validating the pathname. A remote attacker can use a crafted pathname to traverse directories and execute arbitrary commands. The flaw matters because it turns a browser-reachable ActiveX control into a command execution primitive on affected Windows hosts.
Description
Directory traversal vulnerability in the LaunchProcess function in the LaunchHelp.HelpLauncher.1 ActiveX control in LaunchHelp.dll in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.2, 10.3, and 11 SP1 allows remote attackers to execute arbitrary commands via a pathname in the first argument.
AV:N/AC:M/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote command execution with a public exploit and very high EPSS, tempered by the need for user interaction and the age of the affected product.
What it is
The LaunchHelp.HelpLauncher.1 ActiveX control in LaunchHelp.dll, shipped with AdminStudio in Novell ZENworks Configuration Management 10.2, 10.3 and 11 SP1, passes the first argument to LaunchProcess without validating the pathname. A remote attacker can use a crafted pathname to traverse directories and execute arbitrary commands. The flaw matters because it turns a browser-reachable ActiveX control into a command execution primitive on affected Windows hosts.
Impact
An attacker who can get the control instantiated gains arbitrary command execution in the context of the user running the browser or host process. That can lead to full compromise of the workstation and any credentials or management access it holds.
Attack surface
Reached remotely over the network through the ActiveX control, typically by luring a user to a malicious or compromised web page that instantiates LaunchHelp.HelpLauncher.1. No authentication is required, but the CVSS vector marks access complexity as medium and the attack depends on the victim's browser loading the control, so user interaction is effectively required.
Exploitation
Not listed in CISA KEV and no ransomware association is documented, but a public Exploit-DB entry exists and EPSS is very high (0.484, 98.8th percentile), indicating substantial observed or expected exploitation activity.
What to do
- Apply the Novell patch referenced in vendor advisory KB 7009570 for ZENworks Configuration Management 10.2, 10.3 and 11 SP1.
- If patching is delayed, disable or kill-bit the LaunchHelp.HelpLauncher.1 ActiveX control in Internet Explorer and block its CLSID via Group Policy.
- Restrict browser use of ActiveX controls and enforce allow-listing so untrusted sites cannot instantiate local controls.
- Limit user privileges on ZENworks-managed endpoints so command execution does not yield administrative rights.
- Monitor vendor advisories for updated guidance if the affected versions are still in service.
Detection
- Hunt for processes spawned by browser or host processes that load LaunchHelp.dll, especially with command-line arguments containing traversal sequences such as ..\ or ../.
- Audit endpoint logs and EDR telemetry for LaunchHelp.dll or the LaunchHelp.HelpLauncher.1 CLSID being loaded outside expected AdminStudio/ZENworks workflows.
- Review web proxy and DNS logs for users visiting sites known to host the Exploit-DB 19718 proof-of-concept or similar ActiveX exploit pages.
- Check for unexpected child processes (cmd.exe, powershell.exe, wscript.exe) originating from iexplore.exe or other processes hosting the control.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-2657 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-2657), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.