vendor:
NMS DVD Burning SDK Activex
by:
Nine:Situations:Group::bruiser
7.5
CVSS
HIGH
Remote Code Execution
94
CWE
Product Name: NMS DVD Burning SDK Activex
Affected Version From: CDBurnerXP 4.2.1.976
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: IE6
2008
NuMedia Soft NMS DVD Burning SDK Activex (NMSDVDX.dll) remote exploit
The NuMedia Soft NMS DVD Burning SDK Activex (NMSDVDX.dll) is vulnerable to a remote code execution vulnerability. An attacker can use the “EnableLog” method to overwrite a specified file and the “LogMessage” one to write new lines on it. Through the Help and Support Center and the pluggable “hcp://” protocol, the attacker can launch their file. The Help Center will host the page with elevated privileges, allowing the page to script arbitrary controls with no prompts presented to the user.
Mitigation:
An “unlicensed software” box appears, however, if the user closes it or clicks “OK”, the code will run normally.