Race condition in the Enterprise Tree ActiveX control (EnterpriseControls.dll 11.5.0.313) in Crystal Reports XI Release 2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the SelectedSession method, which triggers a buffer overflow.
Threat-Mapped Scoring
Score: 1.9
Priority: P3 - Important (Medium)
S9 – Sabotage of System/App
S10 – Denial of Service (+0.1 bonus)
EPSS
Score: 0.14004 Percentile:
0.94011
CVSS Scoring
CVSS v2 Score: 9.3
Severity:
Mapped CWE(s)
CWE-120
: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
CWE-362
: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
All CAPEC(s)
CAPEC-10: Buffer Overflow via Environment Variables