AVEVA InduSoft Web Studio Remote Command Execution Exploit

The MTCheckFileFunctionsTimeout function in UniSoft.dll does not check the user-supplied executable file name that is used to create a process. If the file name is already a full path, it will be passed as the lpCommandLine parameter to a CreateProcessW call.
Exploit Type - Old
Exploits/Remote
Exploit Platform
Exploit Type
Product Name