vendor:
Edraw PDF Viewer Component
by:
Jambalaya of Nevis Labs
7,5
CVSS
HIGH
Remote code execution
94
CWE
Product Name: Edraw PDF Viewer Component
Affected Version From: Edraw PDF Viewer Component < 3.2.0.126
Affected Version To: Edraw PDF Viewer Component < 3.2.0.126
Patch Exists: YES
Related CWE: N/A
CPE: ocxt.com/download/officeviewer.cab#6,0,612,1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Edraw PDF Viewer Component ActiveX Remote code execution vulnerability
The vulnerability exists due to FtpConnect() function, which could download any file from remote FTP server and put on user's disk.Malicious user could download trojan and put into "startup" folder so that the trojan will run up when user's computer restart. Successful exploitation requires that the target user browse to a malicious web page.
Mitigation:
Set a killbit for this ActiveX.