Microsoft Threat Intelligence’s Post

Microsoft researchers discovered two vulnerabilities in Rockwell Automation’s PanelView Plus that could be remotely exploited by attackers to allow remote code execution (RCE) and denial of service (DoS). PanelView Plus devices are graphic terminals, also known as human machine interface (HMI), used in the industrial sector. Both vulnerabilities are related to custom classes in PanelView Plus. The RCE vulnerability involves two custom classes that could be used to upload and load a malicious DLL into the device. The DoS vulnerability takes advantage of the same custom class to send a crafted buffer that the device is unable to handle properly, thus leading to a DoS. Microsoft reported these findings to Rockwell Automation in May and July 2023, and Rockwell Automation published security patches to address the vulnerabilities in September and October 2023. We’re sharing our research to help developers, vendors, and the industry in general to avoid or detect similar issues in their systems. Read our latest blog to get our analysis of the vulnerabilities, as well as mitigation and protection guidance for defenders: https://msft.it/6046l8Ufn

Vulnerabilities in PanelView Plus devices could lead to remote code execution | Microsoft Security Blog

Vulnerabilities in PanelView Plus devices could lead to remote code execution | Microsoft Security Blog

microsoft.com

Wadï Mami

ingénieur dev & études

4d

I have already contacted Microsoft more than once l Mean (MSRC). But nothing is done I considered as a vulnerability but MSRC considered it as a malware. Brief what do you think if shutdown command is invoked at Windows start-up you can not use your pc or laptop any more. Any time you start it it shutdown. Microsoft must disable Shutdown command use at Windows start-up  https://didipostmanprojects.blogspot.com/2022/04/shutdown-windows-security-threat.html?m=1

Like
Reply

To view or add a comment, sign in

Explore topics