Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-19165

Опубликовано: 29 апр. 2020
Источник: nvd
CVSS3: 7.2
CVSS2: 6.5
EPSS Низкий

Описание

AxECM.cab(ActiveX Control) in Inogard Ebiz4u contains a vulnerability that could allow remote files to be downloaded and executed by setting arguments to the activeX method. Download of Code Without Integrity Check vulnerability in ActiveX control of Inogard Co,,LTD Ebiz4u ActiveX of Inogard Co,,LTD(AxECM.cab) allows ATTACKER to cause a file download to Windows user's folder and execute. This issue affects: Inogard Co,,LTD Ebiz4u ActiveX of Inogard Co,,LTD(AxECM.cab) version 1.0.5.0 and later versions on windows 7/8/10.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:inogard:activex:*:*:*:*:*:*:*:*
Версия до 1.0.5.0 (исключая)

Одно из

cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_7:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_8:-:*:*:*:*:*:*:*

EPSS

Процентиль: 47%
0.00245
Низкий

7.2 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-494
CWE-494

Связанные уязвимости

github
больше 3 лет назад

AxECM.cab(ActiveX Control) in Inogard Ebiz4u contains a vulnerability that could allow remote files to be downloaded and executed by setting arguments to the activeX method. Download of Code Without Integrity Check vulnerability in ActiveX control of Inogard Co,,LTD Ebiz4u ActiveX of Inogard Co,,LTD(AxECM.cab) allows ATTACKER to cause a file download to Windows user's folder and execute. This issue affects: Inogard Co,,LTD Ebiz4u ActiveX of Inogard Co,,LTD(AxECM.cab) version 1.0.5.0 and later versions on windows 7/8/10.

EPSS

Процентиль: 47%
0.00245
Низкий

7.2 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-494
CWE-494