CVE-2017-12969: Avaya IP Office Contact Center

High severity, CVSS 8.8. EPSS: 10.1% chance of exploitation in the next 30 days.

Buffer overflow in the ViewerCtrlLib.ViewerCtrl ActiveX control in Avaya IP Office Contact Center before 10.1.1 allows remote attackers to cause a denial of service (heap corruption and crash) or execute arbitrary code via a long string to the open method.

Affected products

  • Avaya IP Office Contact Center: version 9.1 only; version 9.1.0 only; version 9.1.0.2209.1540 only; version 9.1.6 only; version 9.1.7 only; version 9.1.8 only; …

Published 2017-11-10. Last modified 2026-06-17.