ZeroHour

CVE-2021-26608

CVSS 3.1
9.8 critical
EPSS
<1%p46
Published
()
Modified
Description

An arbitrary file download and execution vulnerability was found in the HShell.dll of handysoft Co., Ltd groupware ActiveX module. This issue is due to missing support for integrity check of download URL or downloaded file hash.

Vendors
handysoft
Products
hshell
Weakness
CWE-353, CWE-345
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.