vendor:
2X Client for RDP
by:
7.5
CVSS
HIGH
ActiveX Control Remote Code Execution
119
CWE
Product Name: 2X Client for RDP
Affected Version From: 10.1.1204
Affected Version To: 10.1.1204
Patch Exists: NO
Related CWE:
CPE: 2x:2x_client_for_rdp:10.1.1204
Platforms Tested: Windows Vista SP2, Windows Server 2003 r2 sp2, Internet Explorer 8
2X Client for RDP 10.1.1204 ClientSystem Class ActiveX Control
The 2X Client for RDP 10.1.1204 ActiveX Control allows remote attackers to download and execute arbitrary files by specifying a URL of a .msi installer in the InstallClient method, leading to remote code execution without user interaction.
Mitigation:
Update to the latest version of the 2X Client for RDP or remove the ActiveX control from the system.