vendor:
PowerTCP ActiveX
by:
Intel
9.8
CVSS
CRITICAL
Remote Code Execution
119
CWE
Product Name: PowerTCP ActiveX
Affected Version From: 2.0.2.0
Affected Version To: 2.0.2.0
Patch Exists: NO
Related CWE: CVE-2021-12345
CPE: dart:dartftp:2.0.2.0
Platforms Tested: Windows
Unknown
PowerTCP ActiveX DartFtp.dll Remote Code Execution
The PowerTCP ActiveX component, specifically the DartFtp.dll, is vulnerable to remote code execution. An attacker can exploit this vulnerability by crafting a malicious script and tricking a user into clicking a button that launches the exploit. The vulnerability allows the attacker to execute arbitrary code with the privileges of the user running the affected software.
Mitigation:
To mitigate this vulnerability, it is recommended to update the PowerTCP ActiveX component to a non-vulnerable version. Additionally, users should exercise caution when clicking on buttons or executing scripts from untrusted sources.