CVE-2020-7812
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Ezhttptrans.ocx ActiveX Control in Kaoni ezHTTPTrans 1.0.0.70 and prior versions contain a vulnerability that could allow remote attacker to download arbitrary file by setting the arguments to the activex method. This can be leveraged for code execution by rebooting the victim’s PC.
Affected (1)
Products: Kaoni: Ezhttptrans
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.0.0.70 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows | All versions |
References (4)
Source: vuln@krcert.or.kr
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.