Lucene search

K
kasperskyKaspersky LabKLA10148
HistoryMar 03, 2010 - 12:00 a.m.

KLA10148 ACE vulnerability in Quiksoft Easymail Objects

2010-03-0300:00:00
Kaspersky Lab
threats.kaspersky.com
29

7.6 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

7.9 High

AI Score

Confidence

Low

0.177 Low

EPSS

Percentile

96.2%

A buffer overflow was found in QuikSoft EasyMail Objects. By exploiting this vulnerability malicious users can execute arbitrary code. This vulnerability can be exploited from the network at a point related to the connection method.

Original advisories

Related products

EasyMail-IMAP4-Object-ActiveX-Control

EasyMail-SMTP-Object-ActiveX-Control

CVE list

CVE-2007-1029 critical

Solution

Update to latest version

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

Affected Products

  • QuickSoft EasyMail Objects versions 6.4 and earlier

7.6 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

7.9 High

AI Score

Confidence

Low

0.177 Low

EPSS

Percentile

96.2%