Lucene search

K
cveMitreCVE-2008-4343
HistorySep 30, 2008 - 5:22 p.m.

CVE-2008-4343

2008-09-3017:22:09
CWE-20
mitre
web.nvd.nist.gov
32
cve-2008-4343
chilkat xml
chilkatutil.ckdata.1
activex control
remote attackers
arbitrary files
execution
remote code execution
hcp:// urls
security vulnerability

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

Low

EPSS

0.147

Percentile

95.8%

The Chilkat XML ChilkatUtil.CkData.1 ActiveX control (ChilkatUtil.dll) 3.0.3.0 and earlier allows remote attackers to create, overwrite, and modify arbitrary files for execution via a call to the (1) SaveToFile, (2) SaveToTempFile, or (3) AppendBinary method. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. NOTE: this can be leveraged for remote code execution by accessing files using hcp:// URLs.

Affected configurations

Nvd
Node
chilkat_softwarechilkat_xml_activex_controlRange3.0.3.0
VendorProductVersionCPE
chilkat_softwarechilkat_xml_activex_control*cpe:2.3:a:chilkat_software:chilkat_xml_activex_control:*:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

Low

EPSS

0.147

Percentile

95.8%

Related for CVE-2008-4343