vendor:
NMSDVDXU ActiveX Control
by:
shinnai
7.5
CVSS
HIGH
Remote Arbitrary File Creation/Execution
94
CWE
Product Name: NMSDVDXU ActiveX Control
Affected Version From: NMSDVDXU.dll <= 1.0.0.13
Affected Version To: NMSDVDXU.dll <= 1.0.0.13
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP
2009
BurnAware NMSDVDXU ActiveX Control Remote Arbitrary File Creation/Execution
BurnAware NMSDVDXU ActiveX Control is vulnerable to Remote Arbitrary File Creation/Execution. An attacker can exploit this vulnerability by using the CLSID {0355854A-7F23-47E2-B7C3-97EE8DD42CD8} and ProgID NMSDVDX.DVDEngineX.1 to create a malicious object and execute arbitrary code. This vulnerability was tested on Windows XP Professional SP3 with Internet Explorer 7.
Mitigation:
The vendor has released a patch to address this vulnerability.