ZeroHour

CVE-2019-12809

CVSS 3.1
8.8 high
EPSS
1%p62
Published
()
Modified
Description

Yes24ViewerX ActiveX Control 1.0.327.50126 and earlier versions contains a vulnerability that could allow remote attackers to download and execute arbitrary files by setting the arguments to the ActiveX method. This can be leveraged for code execution.

Vendors
yes24
Products
viewer activex
Weakness
CWE-494
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.