← Vulnerability feed

Vulnerability record · CVE-2011-4052 · published 5 December 2011

CVE-2011-4052: Indusoft web studio memory buffer overflow vulnerability

Indusoft · Web Studio

Stack-based buffer overflow in CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 allows remote attackers to execute arbitrary code via a crafted 0x15 (aka Remove File) operation for a file with a long name.

9.3 CVSS 2.0 High EPSS 5.7% · top 7.3% CWE-119 · Memory buffer overflow
9.3CVSS 2.0 base score
5.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 allows remote attackers to execute arbitrary code via a crafted 0x15 (aka Remove File) operation for a file with a long name.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-4052 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-0780InduSoft Web Studio NTWebServer path traversal exposes admin passwordsNTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 is vulnerable to directory traversal, allowing remote attackers to read administrative pass…KEVEPSS 75%analysed10.0CVE-2011-4051InduSoft Web Studio CEServer missing authentication allows remote code executionCEServer.exe in the Remote Agent module of InduSoft Web Studio 6.1 and 7.0 does not require authentication. A remote attacker can reach the service a…EPSS 69%analysed10.0CVE-2011-0342Indusoft web studio memory buffer overflow vulnerabilityMultiple buffer overflows in the InduSoft ISSymbol ActiveX control in ISSymbol.ocx 301.1104.601.0 in InduSoft Web Studio 7.0B2 hotfix 7.0.01.04 allow…EPSS 5.9%10.0CVE-2011-1900Indusoft web studio path traversal vulnerabilityDirectory traversal vulnerability in NTWebServer in InduSoft Web Studio 6.1 and 7.x before 7.0+Patch 1 allows remote attackers to execute arbitrary c…EPSS 32%10.0CVE-2011-0488Advantech studio memory buffer overflow vulnerabilityStack-based buffer overflow in NTWebServer.exe in the test web service in InduSoft NTWebServer, as distributed in Advantech Studio 6.1 and InduSoft W…EPSS 8.6%9.8CVE-2018-8840Indusoft web studio stack-based buffer overflow vulnerabilityA remote attacker could send a carefully crafted packet in InduSoft Web Studio v8.1 and prior versions, and/or InTouch Machine Edition 2017 v8.1 and …EPSS 8.3%9.3CVE-2011-0340Advantech studio memory buffer overflow vulnerabilityMultiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distribute…EPSS 32%7.8CVE-2013-1627Advantech studio path traversal vulnerabilityAbsolute path traversal vulnerability in NTWebServer.exe in Indusoft Studio 7.0 and earlier and Advantech Studio 7.0 and earlier allows remote attack…EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2011-4052), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.