CVE-2021-47705

COMMAX UMS Client ActiveX Control 1.7.0.2 contains a heap-based buffer overflow vulnerability that allows attackers to execute arbitrary code by providing excessively long string arrays through multiple functions. Attackers can exploit improper boundary validation in CNC_Ctrl.dll to cause heap corruption and potentially gain system-level access.
CVSS

No CVSS.

Configurations

No configuration.

History

10 Dec 2025, 16:16

Type Values Removed Values Added
References
  • {'url': 'https://www.vulncheck.com/advisories/cncctrl-dllunregisterserver-access-violation', 'source': 'disclosure@vulncheck.com'}
  • () https://www.vulncheck.com/advisories/commax-ums-client-activex-control-cnc-ctrl-dll-heap-buffer-overflow -

09 Dec 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-09 21:15

Updated : 2025-12-12 15:19


NVD link : CVE-2021-47705

Mitre link : CVE-2021-47705

CVE.ORG link : CVE-2021-47705


JSON object : View

Products Affected

No product.

CWE
CWE-787

Out-of-bounds Write