vendor:
Ultra Crypto Component
by:
shinnai
7.5
CVSS
HIGH
Insecure method
20
CWE
Product Name: Ultra Crypto Component
Affected Version From: <= 2.0
Affected Version To: <= 2.0
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP Professional SP2 with Internet Explorer 7
2007
Ultra Crypto Component (CryptoX.dll <= 2.0) "SaveToFile()" Insecure Method
The Ultra Crypto Component (CryptoX.dll) version 2.0 and earlier is vulnerable to an insecure method in the SaveToFile() function. This allows an attacker to save arbitrary data to a file, potentially leading to remote code execution. The vulnerability can be exploited by converting the desired command (e.g., "cmd.exe /c notepad.exe") to hexadecimal format and saving it to a batch file.
Mitigation:
Upgrade to a version of the Ultra Crypto Component (CryptoX.dll) that is not vulnerable.