ZeroHour

CVE-2020-7826

CVSS 3.1
9.8 critical
EPSS
<1%p52
Published
()
Modified
Description

EyeSurfer BflyInstallerX.ocx v1.0.0.16 and earlier versions contain a vulnerability that could allow remote files to be download by setting the arguments to the vulnerable method. This can be leveraged for code execution. When the vulnerable method is called, they fail to properly check the parameters that are passed to it.

Vendors
eyesurfer
Products
bflyinstallerx.ocx
Weakness
CWE-494
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.